I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.
Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.
It is open, oddly enough. It’s just that nobody ships anything other than Microsoft’s keys. You can add your own. It’s just that it is a tedious, manual process.
I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.
Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.
Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.
More like who is implementing it. Take MS out of the picture and set it as an open standard.
It is open, oddly enough. It’s just that nobody ships anything other than Microsoft’s keys. You can add your own. It’s just that it is a tedious, manual process.
Depends on the distro! I could do it in 5 minutes with my bazzite installation: https://docs.bazzite.gg/General/Installation_Guide/secure_boot/
Very happy surprise when setting up my new PC :)
Yeah, Ventoy will import its key for you too. If what you’re using doesn’t come with that utility, you’ll be manually entering in public keys. 😭