top 50 comments

sorted by: hot top controversial new old
[–] 127 points 2 months ago (34 children)

Unpopular opinion but I’m dying on this hill. Secure boot creates more problems than it solves.

  • source
  • hideshow 34 child comments
  • [–] 82 points 2 months ago (19 children)

    I'd argue this is actually a popular opinion. IMO secureboot has just become a way for Microsoft to leverage it's position and keep a strangle hold on industries they have no business being in.

    The whole kernel level anti-cheat on win11 bullshit in the gaming industry is a good example. Essentially locking games to its platform and willing to sacrifice security to do so at our expense.

  • source
  • parent
  • hideshow 19 child comments
  • [–] 24 points 2 months ago (14 children)

    This is especially true on computers where it is impossible to change the signing keys. Smartphones, game consoles, many laptops, some desktops, smart TVs, IoT devices, modern cars, etc.

  • source
  • parent
  • hideshow 14 child comments
  • [+] 2 points 2 months ago* (last edited 2 months ago) (13 children)
  • [–] 9 points 2 months ago (12 children)

    Kind of. You can change the signing key for the operating system, but you cannot change the signing key of the primary bootloader, as that is baked into the SoC.

  • source
  • parent
  • hideshow 12 child comments
  • [–] 4 points 2 months ago (10 children)

    I'm assuming this is why it will forever "warn" me that my phone is running an "insecure" OS?

  • source
  • parent
  • hideshow 10 child comments
  • [–] 8 points 2 months ago (9 children)

    That's moreso because it's using an unofficial key, so the device manufacturer (Google in the case of Pixels) cannot verify the authenticity of the OS you're running.

    If you were able to replace that bootloader with a custom one, then you would be able to disable that message or just use a completely different bootloader like UBoot or EDK2 if it was ported, though.

  • source
  • parent
  • hideshow 9 child comments
  • load more comments (9 replies)
  • load more comments (1 reply)
  • [–] 7 points 2 months ago (3 children)

    Only in tech circles, it says secure and that's enough for most people.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 21 points 2 months ago (2 children)

    Outside of tech circles most people think secure boot looks something like this

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 months ago

    You think that's a safety boot you've got there? It's anything but! It is clearly the bottommost part of a certain powered hazmat suit - why, it's a Hazard Boot! You'll need to ask one of the egg heads whether Secure Boot is a part of its boot sequence, though.

    Poor Gordon Freeman, running around out there somewhere, with just one Hazard Boot. I guess you'll find that his other leg is running with Insecure Foot, then.

  • source
  • parent
  • [–] 5 points 2 months ago (2 children)
  • [–] 6 points 2 months ago (1 child)

    Popular is the wrong question, the correct question is, how many machines is this default on.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 2 months ago

    And, how many people switch to something other than the default? Most W11 users are just going to go with whatever the computer says it's doing without changing anything. They're either ignorant of the options available, or scared of breaking something if they make a change.

  • source
  • parent
  • load more comments (9 replies)
    [–] 71 points 2 months ago (2 children)

    Arch Wiki had pointed out for years that Secure Boot is a flawed mechanism.

  • source
  • hideshow 2 child comments
  • [–] 33 points 2 months ago (6 children)

    11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS).

    This "Trust" is one of my pet peeves. It's $$$.

  • source
  • hideshow 6 child comments
  • [–] 18 points 2 months ago (1 child)

    I get why you'd dislike that wording, but this is also how all certificate stores work, regardless of whether we're talking Secure Boot, Windows or Linux. Gotta trust the top level as providing legitimate certificates to then trust everything underlying as coming from the correct parties.

    Certificate are something I work with constantly at work and I fucking hate resolving issues with them lol.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 2 months ago (1 child)

    Add this to the pile of reasons why M$ is a joke and people should stop using them. Nothing they make is so good that you need to stick around.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 2 months ago*

    MS has mastered the one thing businesses love which is being perfectly mediocre. If you present a business two pieces of software one that does one thing really well but nothing else, and one that does three things terribly, they'll pick the one that does three things terribly every time. That's the MS design, it smears a thin coating of suck across as broad a surface as possible and then advertises that it does everything.

  • source
  • parent
  • [–] 13 points 2 months ago

    All it takes for it to be 'broken' is to be from Microslop.

  • source
  • [–] 5 points 2 months ago

    Few years ago I watched this engineer who used an rp3 to hack a bit locker encryption key.

  • source
  • [–] 4 points 2 months ago
    [–] 3 points 2 months ago

    That's the scary part about security assumptions.

  • source
  • [–] 1 point 2 months ago

    My word of advice; any security implementation by an actor who has a fiscal responsibility and/or incentive is inherently flawed.

    You are handing your keys to a whore.

  • source
  • load more comments
    view more: next ›