Comment by charcircuit
Comment by charcircuit 5 days ago
Laptops already ship secure boot.
Comment by charcircuit 5 days ago
Laptops already ship secure boot.
I hope you are mistaken. It's embarrassing how far behind in security the desktop Linux ecosystem is.
AFAIU (I haven't looked much into it) shim basically exists so that MS signs the shim once (or only a few times when updated), which has the distro public key embedded, which does further verification of the chain (bootloader/kernel) which gets updated more frequently.
Do you really think Laptop makers would buy a whole company to figure out how to remove that option?
Not all. The ones that ship Linux preinstalled and with support don't.