#secureboot — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #secureboot, aggregated by home.social.
-
Microsoft entscheidet, ob dein Linux startet · chrislo.de
https://www.chrislo.de/blog/2026-08-10-07-25-18-microsoft-entscheidet-ob-dein-linux-startet/ -
Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann
Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.https://www.kernel-error.de/2026/08/10/tpm-2-0-unter-linux-tpm2-tools-measured-boot-attestierung/
-
Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann
Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.https://www.kernel-error.de/2026/08/10/tpm-2-0-unter-linux-tpm2-tools-measured-boot-attestierung/
-
@nakal @christin es gab um 2011 herum eine ganze Menge kritische Artikel zu dem Thema, siehe z. B. https://www.fsf.org/campaigns/secure-boot-vs-restricted-boot @fsf #secureboot
-
@nakal @christin es gab um 2011 herum eine ganze Menge kritische Artikel zu dem Thema, siehe z. B. https://www.fsf.org/campaigns/secure-boot-vs-restricted-boot @fsf #secureboot
-
@christin Habe #SecureBoot einfach abgedreht! Mir ist das einfach zu blöd! Ohne Secure Boot gibt's keine Probleme!
-
@christin Habe #SecureBoot einfach abgedreht! Mir ist das einfach zu blöd! Ohne Secure Boot gibt's keine Probleme!
-
@christin "Secure Boot schützt vor einer Bedrohung, die für die meisten Nutzer*innen theoretisch bleibt."
Genau das ☝️ Aber damit läßt sich schön gängeln....
Und mir ist, nach all den Jahren, immer noch unverständlich, wie sich eine ganze komplette Branche darauf einlassen kann, dass eine Firma mit kommerziellen Interessen so eine Macht bekommt, statt das ein gemeinnütziger Verein (oder whatever) gegründet wurde...
-
@christin "Secure Boot schützt vor einer Bedrohung, die für die meisten Nutzer*innen theoretisch bleibt."
Genau das ☝️ Aber damit läßt sich schön gängeln....
Und mir ist, nach all den Jahren, immer noch unverständlich, wie sich eine ganze komplette Branche darauf einlassen kann, dass eine Firma mit kommerziellen Interessen so eine Macht bekommt, statt das ein gemeinnütziger Verein (oder whatever) gegründet wurde...
-
Microsoft entscheidet, ob dein Linux startet
Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch
Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!
https://www.chrislo.de/blog/2026-08-10-07-25-18-microsoft-entscheidet-ob-dein-linux-startet/
#chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd
-
Microsoft entscheidet, ob dein Linux startet
Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch
Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!
https://www.chrislo.de/blog/2026-08-10-07-25-18-microsoft-entscheidet-ob-dein-linux-startet/
#chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd
-
heise+ | Auswirkungen der neuen Secure-Boot-Zertifikate für Linux | heise online https://www.heise.de/ratgeber/Auswirkungen-der-neuen-Secure-Boot-Zertifikate-fuer-Linux-11371220.html #heiseplus #SecureBoot #Linux :tux:
-
heise+ | Auswirkungen der neuen Secure-Boot-Zertifikate für Linux | heise online https://www.heise.de/ratgeber/Auswirkungen-der-neuen-Secure-Boot-Zertifikate-fuer-Linux-11371220.html #heiseplus #SecureBoot #Linux :tux:
-
heise+ | FAQ: Desinfec’t 2026
Wir haben Desinfec’t 2026 vollständig überarbeitet. Hier bündeln wir die Antworten auf häufig gestellte Fragen.
#ct #Desinfect #Hardware #IT #Linux #SecureBoot #UEFI #USBStick #news
-
heise+ | FAQ: Desinfec’t 2026
Wir haben Desinfec’t 2026 vollständig überarbeitet. Hier bündeln wir die Antworten auf häufig gestellte Fragen.
#ct #Desinfect #Hardware #IT #Linux #SecureBoot #UEFI #USBStick #news
-
I've updated my tutorial on how to enable SecureBoot on Gentoo using shim & GRUB, there's a few significant changes compared to the first version I made:
- There are less manual steps as I rely more on the improvements in Gentoo's GRUB package
- There is no need to regenerate the bootloader when installing or removing kernels
- Post-install scripts are provided to automatically update both bootloadershttps://www.setphaserstostun.org/posts/secure-boot-on-gentoo-with-shim-grub/
-
I've updated my tutorial on how to enable SecureBoot on Gentoo using shim & GRUB, there's a few significant changes compared to the first version I made:
- There are less manual steps as I rely more on the improvements in Gentoo's GRUB package
- There is no need to regenerate the bootloader when installing or removing kernels
- Post-install scripts are provided to automatically update both bootloadershttps://www.setphaserstostun.org/posts/secure-boot-on-gentoo-with-shim-grub/
-
Why do I feel like anything with the word “secure” in its name isn’t actually safe at all?
source: arstechnica.com/security/2026/…
The images are known as #shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the #UEFI (Unified Extensible #Firmware Interface) of the device’s #motherboard. The gaffe is the result of the failure by #Microsoft, which oversees the #signing of shims, to revoke the publicly available images once vulnerabilities were found in them.
#news #security #boot #cybersecurity #hack #hacker #software #vulnerability #fail #bios #secureboot #computer #laptop #notebook
-
heise+ | Desinfec’t 2026: Ein Blick unter die Haube
Wir haben unser Live-System zur Schädlingsjagd auf Windows-PCs erneuert. Dieser Artikel blickt technisch auf die Neuerungen und die Auswirkungen für Nutzer.
#Desinfect #IT #Linux #SecureBoot #Sicherheitslücken #Ubuntu #Updates #Virenscanner #Windows #news
-
heise+ | Desinfec’t 2026: Ein Blick unter die Haube
Wir haben unser Live-System zur Schädlingsjagd auf Windows-PCs erneuert. Dieser Artikel blickt technisch auf die Neuerungen und die Auswirkungen für Nutzer.
#Desinfect #IT #Linux #SecureBoot #Sicherheitslücken #Ubuntu #Updates #Virenscanner #Windows #news
-
Frog and Toad Are Chainloaded
frog put the UEFI app signatures in a box. there. now we will not boot any more unsigned UEFI apps. but we can disable SecureBoot said toad. that is true said frog. that is true. frog knew. frog always knew. the box was never locked. toad found the off switch in four seconds. three weeks of signed shim work gone. frog does not cry frog just stares at the mokutil prompt
-
Frog and Toad Are Chainloaded
frog put the UEFI app signatures in a box. there. now we will not boot any more unsigned UEFI apps. but we can disable SecureBoot said toad. that is true said frog. that is true. frog knew. frog always knew. the box was never locked. toad found the off switch in four seconds. three weeks of signed shim work gone. frog does not cry frog just stares at the mokutil prompt
-
In 2011 Microsoft seems to have attempted to prevent installation of alternative operating systems on PCs using a new technology called UEFI "Secure Boot". The worst case scenario never materialized and installing "alternative" operating systems is still possible.
5/21
-
In 2011 Microsoft seems to have attempted to prevent installation of alternative operating systems on PCs using a new technology called UEFI "Secure Boot". The worst case scenario never materialized and installing "alternative" operating systems is still possible.
5/21
-
Secure Boot: Die bittere Wahrheit
Bereits die UEFI genannte Erweiterung des guten alten BIOS litt und leidet unter unnötiger Komplexität und damit zwangsläufig unter diversen Sicherheitslücken. Manch eine von denen riecht, als ob sie nicht einfach auf handwerkliche Fehler zurückgeht oder der überbordenden Komplexität geschuldet ist, sondern eine absichtliche Hintertür darstellen könnte. Eines der Probleme war und ist, dass Schädlinge von Windows aus bis auf das UEFI durchgreifen können und sich dort dauerhaft einnisten. So können sie sogar Neuinstallationen überleben. - Zum angeblichen Schutz des UEFI hat Microsoft (MS) Secure Boot (SB) ersonnen und mit seiner Marktmacht auch durchgesetzt. ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/07/18/secure-boot-die-bittere-wahrheit/
-
Secure Boot: Die bittere Wahrheit
Bereits die UEFI genannte Erweiterung des guten alten BIOS litt und leidet unter unnötiger Komplexität und damit zwangsläufig unter diversen Sicherheitslücken. Manch eine von denen riecht, als ob sie nicht einfach auf handwerkliche Fehler zurückgeht oder der überbordenden Komplexität geschuldet ist, sondern eine absichtliche Hintertür darstellen könnte. Eines der Probleme war und ist, dass Schädlinge von Windows aus bis auf das UEFI durchgreifen können und sich dort dauerhaft einnisten. So können sie sogar Neuinstallationen überleben. - Zum angeblichen Schutz des UEFI hat Microsoft (MS) Secure Boot (SB) ersonnen und mit seiner Marktmacht auch durchgesetzt. ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/07/18/secure-boot-die-bittere-wahrheit/
-
This Week in Security: Another Record Patch Tuesday, LAME is More Secure, Secure Boot is Less Secure, and Milk Malware
-
This Week in Security: Another Record Patch Tuesday, LAME is More Secure, Secure Boot is Less Secure, and Milk Malware
-
🔓 SIGINT // Cybersecurity Watch — 2026-07-17
11 legacy Microsoft-signed Linux UEFI shims can bypass Secure Boot, and no one knows how many vulnerable shims remain in the wild.
https://www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/
#UEFI #SecureBoot #Linux #InfoSec -
#Microsoft’s #SecureBoot has been broken for a decade and no one noticed until now
-
#Microsoft’s #SecureBoot has been broken for a decade and no one noticed until now
-
Just delighted to see that up until 5 min ago, this laptop had #SecureBoot signatures from trustworthy organisation such as, uh… Baramundi Management Suite, EAZ EasyFix, Spyrus WTGCreator of course and who could forget WhiteCanyon blancco!
-
Microsoft’s #SecureBoot has been broken for a decade and no one noticed until now
#security #Microsoft -
Microsoft’s #SecureBoot has been broken for a decade and no one noticed until now
#security #Microsoft -
Feeling really glad the free and open source software community was forced to put so much effort into #SecureBoot right now. Microslop proving time again to be a worthy partner in all this.
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
-
Feeling really glad the free and open source software community was forced to put so much effort into #SecureBoot right now. Microslop proving time again to be a worthy partner in all this.
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
-
More Secure Boot failures: Microsoft never revoked some shim signing keys that were compromised years ago
https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/
#secureboot #computers #microsoft #security #linux #- -
Linus #Torvalds' justification is security: If secure boot is enabled, this must mean that the user does not wish the memory to be filled with data from the disk because it is untrusted. (Correct me if I'm wrong.)
However, is it really still part of the boot process when you load the #SwapFile into memory?
Also, if you distrust the disk, why would you even load the operating system from it? By Linus' logic, #Linux should only support #SecureBoot in combination with disk encryption. 🤔
-
Linus #Torvalds' justification is security: If secure boot is enabled, this must mean that the user does not wish the memory to be filled with data from the disk because it is untrusted. (Correct me if I'm wrong.)
However, is it really still part of the boot process when you load the #SwapFile into memory?
Also, if you distrust the disk, why would you even load the operating system from it? By Linus' logic, #Linux should only support #SecureBoot in combination with disk encryption. 🤔
-
Something I terribly hate about #Linux is its unwillingness to hibernate with #SecureBoot enabled. I don't want to keep my computer idle for several hours just to preserve the states of the currently running programs.
#Windows' user experience is so much more convenient here: It automatically shuts down to conserve energy when you don't use the computer for a while, and when you boot again, it restores everything in memory from the #swap file, so you can continue without measurable interruption.
-
Something I terribly hate about #Linux is its unwillingness to hibernate with #SecureBoot enabled. I don't want to keep my computer idle for several hours just to preserve the states of the currently running programs.
#Windows' user experience is so much more convenient here: It automatically shuts down to conserve energy when you don't use the computer for a while, and when you boot again, it restores everything in memory from the #swap file, so you can continue without measurable interruption.
-
Ein gravierendes Problem bei #SecureBoot ermöglichte über zehn Jahre lang Angriffe auf #Windows und Linux. Microsoft hat die veralteten Komponenten nun endlich gesperrt. https://winfuture.de/news,159982.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
The Debian 13.6 point release is here. Upgrade now to secure your Linux kernel, Apache server, and resolve critical UEFI Secure Boot certificate issues.
#Debian #Linux #SecureBoot #SysAdmin #OpenSource
https://meterpreter.org/debian-13-6-point-release/?utm_source=mastodon&utm_medium=jetpack_social
-
Auf einigen PCs pausiert #Microsoft jetzt den #Rollout neuer #SecureBoot-#Zertifikate. Inkompatible Firmware führt teils zu schweren Startproblemen. Betroffene müssen auf OEM-Updates warten. #Windows11 https://winfuture.de/news,159912.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia