this post was submitted on 15 Jul 2026
252 points (98.1% liked)

Technology

86930 readers
3043 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Zarobi@aussie.zone 47 points 3 weeks ago (7 children)

Because it's proprietary and in 99% of cases actually means "Windows Boot", and isn't very compatible with other OS. Windows is basically in charge of the entire technology and doesn't have a history of being friendly to other OS.

For a while Linux was completely blocked by this setting, which was yet another technical barrier to getting into Linux because you had to fuck around in your scary UEFI settings otherwise your PC would be soft-bricked after installing Linux. Nowadays it's slightly supported by some distributions but Microsoft could of course change it at any time.

Further reading: https://wiki.ubuntu.com/UEFI/SecureBoot

[–] orclev@lemmy.world 19 points 3 weeks ago (6 children)

The way it should work is that during the OS install the OS can ask to have a cert added to the keystore at which point UEFI pops up a screen that says something like:

An application has requested to add a new certificate to secure boot which will allow new software to run at boot up. This usually happens when installing or updating an OS. If you would like to allow this press and hold <5 randomly selected letters> on the keyboard for 5 seconds. If you don't want to allow this press and hold escape for 3 seconds.

This would at least be a vendor agnostic way of enrolling certificates instead of the MS certificate just always being pre-installed. It should also of course be publicly documented exactly how the process works so everyone can use it.

[–] addie@feddit.uk 8 points 3 weeks ago (3 children)

Problem being, of course, that you can add more certificates, but you can't revoke the original M$ one. And since it's vulnerable and you can't get rid, then these exploits still work and there's nothing you can do to stop it.

[–] orclev@lemmy.world 3 points 3 weeks ago

You should be able to remove any or all the certs as well, although I could see an argument for requiring you to enter the BIOS to do that.

load more comments (2 replies)
load more comments (4 replies)
load more comments (4 replies)