• programmerlexi@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      5 hours ago

      My secure boot with hibernate works perfectly fine, or rather it did work fine before hibernate started freezing my system, secure boot or not.

  • RiQuY@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    17 hours ago

    imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can’t recover your data or if they want to put a virus in your pc they literally can’t.

    I don’t see any reason to put secure boot on a desktop PC that’s already locked inside your house.

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 hour ago

        disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition

      • Auth@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        8 hours ago

        They never said it did. Only that a laptop with encrypted drives is where secure boot makes sense. The OS can be as secure as it wants but if the drive isnt encrypted it can be accessed.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      10 hours ago

      Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.

      For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.

    • SomeLemmyUser@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      15 hours ago

      That’s exactly mz setup, as I need to leave my work laptop unauthorized in a shared space for prolonged periods.

      Can’t set up secure boot though because even fckin lenovo doesn’t provide the needed bios options for Linux nowadays -.-

  • Richard@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    18 hours ago

    Deciding to turn on secureboot on any distro that doesn’t support it out of the box is always a mistake.

    Still have nightmares from that one time i tried doing it under nixOS…

    • Billegh@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      20 hours ago

      I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.

      Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        19 hours ago

        Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.

        • libewa@feddit.org
          link
          fedilink
          arrow-up
          0
          ·
          19 hours ago

          UEFI doesn’t forbid you from implementing additional file systems, it just requires everyone to support UEFI-FAT. iBoot for example supports booting from HFS volumes.