home.social

#secureboot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secureboot, aggregated by home.social.

fetched live
  1. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  2. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  3. @christin Habe #SecureBoot einfach abgedreht! Mir ist das einfach zu blöd! Ohne Secure Boot gibt's keine Probleme!

    #Linux #Mint #Microsoft #Windows

  4. @christin Habe #SecureBoot einfach abgedreht! Mir ist das einfach zu blöd! Ohne Secure Boot gibt's keine Probleme!

    #Linux #Mint #Microsoft #Windows

  5. @christin "Secure Boot schützt vor einer Bedrohung, die für die meisten Nutzer*innen theoretisch bleibt."

    Genau das ☝️ Aber damit läßt sich schön gängeln....

    Und mir ist, nach all den Jahren, immer noch unverständlich, wie sich eine ganze komplette Branche darauf einlassen kann, dass eine Firma mit kommerziellen Interessen so eine Macht bekommt, statt das ein gemeinnütziger Verein (oder whatever) gegründet wurde...

    #SecureBoot #Microsoft #Linux

  6. @christin "Secure Boot schützt vor einer Bedrohung, die für die meisten Nutzer*innen theoretisch bleibt."

    Genau das ☝️ Aber damit läßt sich schön gängeln....

    Und mir ist, nach all den Jahren, immer noch unverständlich, wie sich eine ganze komplette Branche darauf einlassen kann, dass eine Firma mit kommerziellen Interessen so eine Macht bekommt, statt das ein gemeinnütziger Verein (oder whatever) gegründet wurde...

    #SecureBoot #Microsoft #Linux

  7. Microsoft entscheidet, ob dein Linux startet

    Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch

    Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!

    chrislo.de/blog/2026-08-10-07-

    #chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd

  8. Microsoft entscheidet, ob dein Linux startet

    Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch

    Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!

    chrislo.de/blog/2026-08-10-07-

    #chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd

  9. heise+ | Auswirkungen der neuen Secure-Boot-Zertifikate für Linux

    Nach 15 Jahren sind die Secure-Boot-Zertifikate abgelaufen, mit denen auch Linux-Bootloader signiert sind. Wir erklären, welche Auswirkungen das auf Linux hat.

    heise.de/ratgeber/Auswirkungen

    #BIOS #Debian #Hardware #IT #Linux #SecureBoot #Ubuntu #news

  10. heise+ | Auswirkungen der neuen Secure-Boot-Zertifikate für Linux

    Nach 15 Jahren sind die Secure-Boot-Zertifikate abgelaufen, mit denen auch Linux-Bootloader signiert sind. Wir erklären, welche Auswirkungen das auf Linux hat.

    heise.de/ratgeber/Auswirkungen

    #BIOS #Debian #Hardware #IT #Linux #SecureBoot #Ubuntu #news

  11. I've updated my tutorial on how to enable SecureBoot on Gentoo using shim & GRUB, there's a few significant changes compared to the first version I made:
    - There are less manual steps as I rely more on the improvements in Gentoo's GRUB package
    - There is no need to regenerate the bootloader when installing or removing kernels
    - Post-install scripts are provided to automatically update both bootloaders

    setphaserstostun.org/posts/sec

    #Gentoo #SecureBoot

  12. I've updated my tutorial on how to enable SecureBoot on Gentoo using shim & GRUB, there's a few significant changes compared to the first version I made:
    - There are less manual steps as I rely more on the improvements in Gentoo's GRUB package
    - There is no need to regenerate the bootloader when installing or removing kernels
    - Post-install scripts are provided to automatically update both bootloaders

    setphaserstostun.org/posts/sec

    #Gentoo #SecureBoot

  13. Why do I feel like anything with the word “secure” in its name isn’t actually safe at all?

    source: arstechnica.com/security/2026/…

    The images are known as #shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the #UEFI (Unified Extensible #Firmware Interface) of the device’s #motherboard. The gaffe is the result of the failure by #Microsoft, which oversees the #signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

    #news #security #boot #cybersecurity #hack #hacker #software #vulnerability #fail #bios #secureboot #computer #laptop #notebook

  14. Frog and Toad Are Chainloaded

    frog put the UEFI app signatures in a box. there. now we will not boot any more unsigned UEFI apps. but we can disable SecureBoot said toad. that is true said frog. that is true. frog knew. frog always knew. the box was never locked. toad found the off switch in four seconds. three weeks of signed shim work gone. frog does not cry frog just stares at the mokutil prompt

    #infosec #SecureBoot

  15. Frog and Toad Are Chainloaded

    frog put the UEFI app signatures in a box. there. now we will not boot any more unsigned UEFI apps. but we can disable SecureBoot said toad. that is true said frog. that is true. frog knew. frog always knew. the box was never locked. toad found the off switch in four seconds. three weeks of signed shim work gone. frog does not cry frog just stares at the mokutil prompt

    #infosec #SecureBoot

  16. In 2011 Microsoft seems to have attempted to prevent installation of alternative operating systems on PCs using a new technology called UEFI "Secure Boot". The worst case scenario never materialized and installing "alternative" operating systems is still possible.

    5/21

    #microsoft #uefi #secureboot

  17. In 2011 Microsoft seems to have attempted to prevent installation of alternative operating systems on PCs using a new technology called UEFI "Secure Boot". The worst case scenario never materialized and installing "alternative" operating systems is still possible.

    5/21

    #microsoft #uefi #secureboot

  18. Secure Boot: Die bittere Wahrheit

    Bereits die UEFI genannte Erweiterung des guten alten BIOS litt und leidet unter unnötiger Komplexität und damit zwangsläufig unter diversen Sicherheitslücken. Manch eine von denen riecht, als ob sie nicht einfach auf handwerkliche Fehler zurückgeht oder der überbordenden Komplexität geschuldet ist, sondern eine absichtliche Hintertür darstellen könnte. Eines der Probleme war und ist, dass Schädlinge von Windows aus bis auf das UEFI durchgreifen können und sich dort dauerhaft einnisten. So können sie sogar Neuinstallationen überleben. - Zum angeblichen Schutz des UEFI hat Microsoft (MS) Secure Boot (SB) ersonnen und mit seiner Marktmacht auch durchgesetzt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #linux #Microsoft #sicherheit #wissen #uefi #secureboot

  19. Secure Boot: Die bittere Wahrheit

    Bereits die UEFI genannte Erweiterung des guten alten BIOS litt und leidet unter unnötiger Komplexität und damit zwangsläufig unter diversen Sicherheitslücken. Manch eine von denen riecht, als ob sie nicht einfach auf handwerkliche Fehler zurückgeht oder der überbordenden Komplexität geschuldet ist, sondern eine absichtliche Hintertür darstellen könnte. Eines der Probleme war und ist, dass Schädlinge von Windows aus bis auf das UEFI durchgreifen können und sich dort dauerhaft einnisten. So können sie sogar Neuinstallationen überleben. - Zum angeblichen Schutz des UEFI hat Microsoft (MS) Secure Boot (SB) ersonnen und mit seiner Marktmacht auch durchgesetzt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #linux #Microsoft #sicherheit #wissen #uefi #secureboot

  20. 🔓 SIGINT // Cybersecurity Watch — 2026-07-17
    11 legacy Microsoft-signed Linux UEFI shims can bypass Secure Boot, and no one knows how many vulnerable shims remain in the wild.
    helpnetsecurity.com/2026/07/14

  21. Just delighted to see that up until 5 min ago, this laptop had #SecureBoot signatures from trustworthy organisation such as, uh… Baramundi Management Suite, EAZ EasyFix, Spyrus WTGCreator of course and who could forget WhiteCanyon blancco!

  22. Feeling really glad the free and open source software community was forced to put so much effort into #SecureBoot right now. Microslop proving time again to be a worthy partner in all this.

    welivesecurity.com/en/eset-res

  23. Feeling really glad the free and open source software community was forced to put so much effort into #SecureBoot right now. Microslop proving time again to be a worthy partner in all this.

    welivesecurity.com/en/eset-res

  24. Linus #Torvalds' justification is security: If secure boot is enabled, this must mean that the user does not wish the memory to be filled with data from the disk because it is untrusted. (Correct me if I'm wrong.)

    However, is it really still part of the boot process when you load the #SwapFile into memory?

    Also, if you distrust the disk, why would you even load the operating system from it? By Linus' logic, #Linux should only support #SecureBoot in combination with disk encryption. 🤔

  25. Linus #Torvalds' justification is security: If secure boot is enabled, this must mean that the user does not wish the memory to be filled with data from the disk because it is untrusted. (Correct me if I'm wrong.)

    However, is it really still part of the boot process when you load the #SwapFile into memory?

    Also, if you distrust the disk, why would you even load the operating system from it? By Linus' logic, #Linux should only support #SecureBoot in combination with disk encryption. 🤔

  26. Something I terribly hate about #Linux is its unwillingness to hibernate with #SecureBoot enabled. I don't want to keep my computer idle for several hours just to preserve the states of the currently running programs.

    #Windows' user experience is so much more convenient here: It automatically shuts down to conserve energy when you don't use the computer for a while, and when you boot again, it restores everything in memory from the #swap file, so you can continue without measurable interruption.

  27. Something I terribly hate about #Linux is its unwillingness to hibernate with #SecureBoot enabled. I don't want to keep my computer idle for several hours just to preserve the states of the currently running programs.

    #Windows' user experience is so much more convenient here: It automatically shuts down to conserve energy when you don't use the computer for a while, and when you boot again, it restores everything in memory from the #swap file, so you can continue without measurable interruption.

  28. Ein gravierendes Problem bei #SecureBoot ermöglichte über zehn Jahre lang Angriffe auf #Windows und Linux. Microsoft hat die veralteten Komponenten nun endlich gesperrt. winfuture.de/news,159982.html?

  29. The Debian 13.6 point release is here. Upgrade now to secure your Linux kernel, Apache server, and resolve critical UEFI Secure Boot certificate issues.

    #Debian #Linux #SecureBoot #SysAdmin #OpenSource

    meterpreter.org/debian-13-6-po

  30. Auf einigen PCs pausiert #Microsoft jetzt den #Rollout neuer #SecureBoot-#Zertifikate. Inkompatible Firmware führt teils zu schweren Startproblemen. Betroffene müssen auf OEM-Updates warten. #Windows11 winfuture.de/news,159912.html?