Comment by egorfine
> allowing you to authenticate the parts of the Linux boot
No, not you. Someone else for you. And that's the scary part.
> allowing you to authenticate the parts of the Linux boot
No, not you. Someone else for you. And that's the scary part.
Yes you. The parts being expanded upon happen after the shim is authenticated by SecureBoot and are fully in your control. The scary part has already happened, Linux distros support SecureBoot right now and have for a while. Right now the current state of the Linux boot process is all the downsides (in your view) of SecureBoot with none of the upsides because very little is authenticated after that.