this post was submitted on 21 Dec 2025
41 points (93.6% liked)
Arch Linux
9327 readers
3 users here now
The beloved lightweight distro
founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
"It works on my system" vs. "I bricked my device because the basic functionality to replace the pre-installed keys was broken or some idiot vendor had signed his hardware with that MS key" is still bad, even when it runs for the vast majority only using their system with pre-installed keys (those are not actually the ones needing the security and it really is just a marketing gimmick) while just a small minority aiming for security gets screwed by shitty implementations.
The intent makes sense, it is a trust chain to ensure the system will only boot if it is not tempered with. We have it on android also, to prevent malicious Kernel and OS changes. Microsoft holding the keys signing is the shit part.