Sergey's Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.world to Linux@programming.dev · 6 months ago

Linux and Secure Boot certificate expiration

lwn.net

external-link
message-square
11
link
fedilink
  • cross-posted to:
  • linux@lemmy.ml
54
external-link

Linux and Secure Boot certificate expiration

lwn.net

cm0002@lemmy.world to Linux@programming.dev · 6 months ago
message-square
11
link
fedilink
  • cross-posted to:
  • linux@lemmy.ml
Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a ke [...]

From: https://techrights.org/n/2025/08/26/The_UEFI_9_11_Part_I_Introduction_to_Impending_Catastrophe_Micr.shtml

alert-triangle
You must log in or # to comment.
  • floofloof@lemmy.ca
    link
    fedilink
    arrow-up
    15
    ·
    6 months ago

    What a terrible system. I have a couple of computers where the vendor provides good update support, but for most of them this is not the case and you’re pretty much stuck with the firmware you get. To tie Secure Boot to such a flaky set of distribution channels seems like very poor planning.

    • onlinepersona@programming.dev
      link
      fedilink
      arrow-up
      18
      arrow-down
      1
      ·
      edit-2
      6 months ago

      Or it’s on purpose to force the purchase of new hardware.

      Anti Commercial-AI license

      • granolabar@kbin.melroy.org
        link
        fedilink
        arrow-up
        9
        ·
        6 months ago

        It is always about the money.

    • Khleedril@cyberplace.social
      link
      fedilink
      arrow-up
      1
      ·
      6 months ago

      @floofloof @cm0002 Poor planning my ass. This was the plan all along. They [expletive] know what they are doing.

  • ook@discuss.tchncs.de
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    14 days ago

    deleted by creator

    • fuckwit_mcbumcrumble@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 months ago

      Was your bios updated in the last few years? Not when you updated it, but when the manufacturer pushed a newer update.

      If it’s older than 2023 then you’re screwed. If it’s been updated since then then you’re probably fine.

      • floofloof@lemmy.ca
        link
        fedilink
        arrow-up
        4
        ·
        6 months ago

        Screwed just means you’ll have to turn off Secure Boot if you ever want to reinstall Linux. And on many PCs the Secure Boot has been so badly implemented it’s pretty worthless anyway. Several of mine have a root key called something like “AMI TEST KEY - DO NOT TRUST” which basically invalidates the whole system and is unfixable by the user.

      • ook@discuss.tchncs.de
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        14 days ago

        deleted by creator

        • silly goose meekah@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          6 months ago

          They’re asking for the newest version of firmware available, not the one you have installed. Check the website of your motherboards manufacturer to see if they have anything.

          • ook@discuss.tchncs.de
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            14 days ago

            deleted by creator

            • silly goose meekah@lemmy.world
              link
              fedilink
              arrow-up
              3
              ·
              6 months ago

              Yeah, as far as I understand it. I think you’re fine if you just turn secure boot off, if that’s an option for you.

              • ook@discuss.tchncs.de
                link
                fedilink
                arrow-up
                4
                ·
                edit-2
                14 days ago

                deleted by creator

    • CCMan1701A@startrek.website
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      i have just revived a system from 2013 with linux, if i turn off secure boot does this matter?

      • f4f4f4f4f4f4f4f4@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 months ago

        No.

  • Infernal_pizza@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 months ago

    Would this not also be an issue for Windows users? Or is the Windows boot loader signed with a different key?

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 776 users / day
  • 1.33K users / week
  • 3.76K users / month
  • 10.7K users / 6 months
  • 1 local subscriber
  • 12.7K subscribers
  • 4.15K Posts
  • 32.6K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org