Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungWe shipped guest play at 17:39 and deleted it at 18:35(21.09.2026 um 13:32 Uhr)
Sichere ProgrammierungBest MCP Servers 2026: 10 Worth Installing (Tested)(21.09.2026 um 13:42 Uhr)
Sichere ProgrammierungThe Resume Is Dying. What's Replacing It?(21.09.2026 um 13:44 Uhr)
Sichere Programmierung38 clamps, four probits, and one coefficient rounded to 15 digits(21.09.2026 um 13:46 Uhr)
Sichere ProgrammierungGmail deletes your SVG logo and Outlook ignores your flexbox(21.09.2026 um 13:47 Uhr)
Sichere Programmierung'2026-27' is a better database key than a date range(21.09.2026 um 13:49 Uhr)
Sichere ProgrammierungThe CoreDNS Black Hole: how one dead DNS pod broke our API gateway(21.09.2026 um 13:53 Uhr)
Sichere ProgrammierungWe shipped guest play at 17:39 and deleted it at 18:35(21.09.2026 um 13:32 Uhr)
Sichere ProgrammierungBest MCP Servers 2026: 10 Worth Installing (Tested)(21.09.2026 um 13:42 Uhr)
Sichere ProgrammierungThe Resume Is Dying. What's Replacing It?(21.09.2026 um 13:44 Uhr)
Sichere Programmierung38 clamps, four probits, and one coefficient rounded to 15 digits(21.09.2026 um 13:46 Uhr)
Sichere ProgrammierungGmail deletes your SVG logo and Outlook ignores your flexbox(21.09.2026 um 13:47 Uhr)
Sichere Programmierung'2026-27' is a better database key than a date range(21.09.2026 um 13:49 Uhr)
Sichere ProgrammierungThe CoreDNS Black Hole: how one dead DNS pod broke our API gateway(21.09.2026 um 13:53 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

How and why is UEFI's Secure Boot useful?

There has been some discussions around SecureBoot recently, which a lot of it prompted by Intel's clearlinux team saying that they do not support Secure Boot. I wanted to clear several misconceptions on the matter. 1) Secure Boot is a…

0
↗ Quelle (reddit.com)
Reagiere als Erste:r — dein Feedback zählt!

There has been some discussions around SecureBoot recently, which a lot of it prompted by Intel's clearlinux team saying that they do not support Secure Boot. I wanted to clear several misconceptions on the matter.

1) Secure Boot is a microsoft product.

No it's not. It's part of the UEFI (Unified Extensible Firmware Interface) standard that evolved out of Intel's EFI replacement for legacy IBM-PC bios.

UEFI is a defined interface that is presented by a motherboard's firmware to allow conforming operating systems to interact with the platform hardware. Secure Boot is nothing more than a standard for comparing cryptographic signatures on bootable executables and some OS code against a database of keys. https://www.intel.com/content/www/us/en/support/articles/000006942/boards-and-kits/desktop-boards.html . In pretty much all x86 motherboards (by which I mean I can't find any exception,) the key database is entirely controllable by the end user. If you want to add your own key, you can. If you want to delete microsoft's key, you can. The only way that microsoft is involved is that 1) the majority of motherboards ship by default with MS's key, and 2) for a computer to be designated "Certified for Windows 8 or 10 or whatever" it has to ship with Secure Boot enabled by default and have Microsoft's key. It does not prevent user management of the keys.

Many distros have partnered with windows to piggy-back off their keys since they're distributed by default, but this is only relevant for REALLY new users who cannot manage their own key store. It's entirely possible to get the signing keys of your distro or to sign your own stuff without using MS's key at all.

2) Secure boot is meant for enforcing DRM

Secure boot isn't even capable of enforcing DRM by itself. Once the OS is loaded Secure Boot doesn't do anything, it is only capable of restricting execution of boot loaders and OS kernel / modules. Most people confuse the criticism of secure boot with the criticism of hardware TPMs (trusted platform module). A TPM is a hardware device that contains private cryptographic keys with a defined interface for decrypting data without exposing your private key. In theory a company can require a TPM that does not expose an interface for user management of the keys and use it to restrict what devices are authorized to use its software or view media. Essentially a dongle. For that to be effective you'd have to enable both a TPM and a bastardized version of secure-boot that only allows heavily restricted operating systems to boot so that someone could not just load the software, find the unencrypted version of the software / media in RAM, and dump a cracked version that bypasses the DRM. But there are no examples of this type of thing being done on consumer PCs since most don't come with a TPM, and most users are not computer savy enough to understand how to buy / install / use one.

3) secure boot doesn't protect anything or isn't useful.

It is entirely possible that your specific use case and risk tolerance is such that it is not an overall benefit for you to use secure-boot, but there are real benefits to it. If you dual boot your computer with both Windows and Linux, and have encrypted your Linux main drive, you still have unencrypted files that are used to bootstrap your computer enough to unencrypted those files. Even without a filesystem driver in windows that can read a linux partition, there still exists a theoretical attack where someone could compromise your windows OS, modify your initramfs, and put in some code to sniff your decryption password, writing it back onto your windows system to be retrieved the next time you boot into your compromised windows. SecureBoot prevents this attack, and even if your windows system is compromised by someone without a private key matching your secure boot key database, your linux boot files cannot be modified. If you only run one Linux distro, it's much less beneficial since a compromised Linux system that allows modifying boot files would mean access to anything else, but it would still prevent certain theoretical classes of attack.

I'm certain I missed something, and am open to discussion or debate, but I wanted to clear up a lot of confusion and myths that seems to exist.

submitted by /u/Paul_Aiton
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How and why is UEFI's Secure Boot useful?

Thematisch verwandte Begriffe: UEFIs, Secure, Boot, useful · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94040 | A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this v…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick