Skip to main content



Some Linux users might be interested, reading about this (Subscriber link, that bypasses the Paywall, since I find this information important to spread for awareness):

lwn.net/SubscriberLink/1029767…

„Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft that is set to expire in September. After that point, Microsoft will no longer use that key to sign the shim first-stage UEFI bootloader that is used by Linux distributions to boot the kernel with Secure Boot. But the replacement key, which has been available since 2023, may not be installed on many systems; worse yet, it may require the hardware vendor to issue an update for the system firmware, which may or may not happen.“

#linux #secureboot #microsoft #security #servicetweet

This entry was edited (5 months ago)

reshared this

in reply to HowToPhil (Phillip R)

@howtophil @voice

1st: You can always disable secure-boot in UEFI.

2nd: You can enroll your own pubkey and sign your boot-loader/kernel yourself.
You can even remove the MS-Key from your UEFI and be entirely independent from any corporation.

3rd: The MS-CA is basically just convinience, so that you don't *need* to do bullet point No. 2 and there's a central party for signing for consumer hardware.

A secure boot process with a safe chain-of-trust is crucial, if you want secure computing.

And nodoby is forcing you to use it. It's optional. (I do use it. I use it with my own keys, together with full-disk-encryption as a safety measure. see burningboard.net/@Larvitz/1148…)

This entry was edited (5 months ago)
in reply to Larvitz

@howtophil @Voice anyone have good guides for 1 and 2 ( disable UEFI and enrolling your own pubkey ) for those unfamiliar with the intricacies of the whole thing?
in reply to FLOX Advocate

The Arch Linux wiki has a pretty comprehensive article about UEFI and secure boot - including how to enroll your own keys and possible gotchas.

wiki.archlinux.org/title/Unifi…

in reply to FLOX Advocate

1 will vary based on the laptop. In most UEFIs it’s where you configure boot devices.

For 2, Linux-surface has a decent overview, the tldr is they’re x509 certificates and you use “mokutil” github.com/linux-surface/linux-surface/wiki/Secure-Boot












The intolerable memes of Alligator Alcatraz

The giddy, extremely online cruelty around the Florida detention facility reveals contempt for popular opinion.



🤘 War irgendwie schon länger absehbar. Hoffentlich steckt das jemand Gas-Kathi ...🤦

Ich bin um 2000 herum bei einem Event von M auf dem Alexanderplatz mit der V-Klasse (H2 Fuelcell) gefahren. Habe später diverse Symposien von H2-Autobauern besucht - die meisten in Shanghai übrigens – und ab dem Durchstarten der Elektromobilität (in China) war eigentlich allen klar, dass die Technologie im PKW ganz sicher NICHT kommt. 😎

Fazit: Tja ... 🤪

🤘 :solar_energy: 🤘

heise.de/news/Elektroauto-Stel…

in reply to SvenTetzlaff (翁 辞文)

bloß nicht #gaskathi erzählen. Sobald die das gesteckt bekommt, fängt die an, alle Hebel in Bewegung zu setzen, schnell noch Gas Lieferverträge zur Erzeugung von grauen Wasserstoff abzuschließen. Bevor dieses Geschäftsfeld der Gasindustrie komplett tot ist. BMW wahrt ja noch den Anschein.


Azerbaijan Preparing Documents to File International Lawsuits Against Russia Over AZAL Passenger Plane Disaster — Ilham Aliyev byteseu.com/1211240/ #Azerbaijan #Azərbaycan #AzərbaycanRespublikası #RepublicOfAzerbaijan



Late Stage Capitalism

english.elpais.com/culture/202…




20 July 1943 | 1,000 Jews deported from Drancy in German-occupied France arrived at Auschwitz. After the selection, 369 men & 191 women were registered in the camp. The remaining 440 people were murdered in a gas chamber.

Among them was 16-month-old Claudine Ruben.



🤘 Jedes Büro braucht einen (J)METAL-Server. Wirklich JEDES!

🤘 🎸 🤘





Street interview with an AKP: “You can also feed your belly with cheese, bread. As long as you take care of the soil. Ozgur Ozel will be prepared in Silivri. byteseu.com/1211237/ #RepublicOfTürkiye #Turkey #Türkiye #TürkiyeCumhuriyeti