reshared this
Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a ke [...]LWN.net
By effectively erecting a shield around Israel, Iron Dome and other defense systems grant Israel the impunity to act without restraint. That doesn't save lives, it takes them away by the thousands.
Note to AOC: Iron Dome Is an Offensive Weapon
Watch on Substack: open.substack.com/pub/mitchell…
Or on YouTube: youtu.be/MpacmR5eTbE
The server mastodon.arell.ai is copying the account details of people, and then posting AI nonsense as them.
It likely scrapes the profile information to make the account. So a server block is likely needed.
I made a short (free) 3D game in #godot about being queer. If you're queer, trans, or questioning, I hope this game can give you some comfort.
All original assets and code are open source and in Creative Commons!
Try out Proton Mail, the secure email that protects your privacy: proton.me/mail/TheLinuxEXP
Grab a brand new laptop or desktop running Linux: tuxedocomputers.com/en#
👏 SUPPORT THE CHANNEL:
Get access to a weekly podcast, vote on the next topics I cover, and get your name in the credits:
YouTube: youtube.com/@thelinuxexp/join
Patreon: patreon.com/thelinuxexperiment
Liberapay: liberapay.com/TheLinuxExperime…
Or, you can donate whatever you want: paypal.me/thelinuxexp
👕 GET TLE MERCH
Support the channel AND get cool new gear: the-linux-experiment.creator-s…
🎙️ LINUX AND OPEN SOURCE NEWS PODCAST:
Listen to the latest Linux and open source news, with more in depth coverage, and ad-free! podcast.thelinuxexp.com
🏆 FOLLOW ME ELSEWHERE:
Website: thelinuxexp.com
Mastodon: mastodon.social/web/@thelinuxE…
Pixelfed: pixelfed.social/TLENick
PeerTube: tilvids.com/c/thelinuxexperime…
Discord: discord.gg/mdnHftjkja
00:00 Intro
00:43 Sponsor: Proton
01:54 Linux Mint is working on Wayland
03:26 Youtube's adblock blocker might not be legal
04:52 Fedora 39 gets delayed twice
06:09 OpenSUSE wants to replace its logo
07:41 KDE & GNOME Updates
09:22 New accessibility framework for Linux
10:40 Performance improvements for Linux and drivers
12:57 Gaming News: SteamVR, 3DS emulator perf boost
14:31 Sponsor: Get a PC made to run Linux
15:39 Support the channel
Linux Mint is working on Wayland
Youtube's adblock blocker might not be legal
theregister.com/2023/10/26/pri…
Fedora 39 gets delayed twice
linuxiac.com/fedora-linux-39-r…
linuxiac.com/fedora-39-release…
OpenSUSE wants to replace its logo
linuxiac.com/opensuse-calls-fo…
KDE & GNOME Updates
pointieststick.com/2023/10/27/…
thisweek.gnome.org/posts/2023/…
New accessibility framework for Linux
blogs.gnome.org/a11y/2023/10/2…
Performance improvements for Linux and drivers
phoronix.com/news/Mutter-Nouve…
phoronix.com/news/Mesa-24.0-Fe…
phoronix.com/news/AMD-Ryzen-Fr…
Gaming News: SteamVR, 3DS emulator perf boost
store.steampowered.com/news/ap…
gamingonlinux.com/2023/10/valv…
gamingonlinux.com/2023/10/nint…
Recently I highlighted that the Nintendo 3DS emulator Citra was doing a big move over to Vulkan, giving it a modern rendering system to keep on pushing performance. The latest updates also give a big boost for Linux / Steam Deck.Liam Dawe (GamingOnLinux)
Did you know that there is not only Matt Godbolt's Compiler Explorer at godbolt.org, but also a Decompiler Explorer, appropriately named dogbolt.org, which compares the output of Ghidra, BinaryNinja, IDA and other decompilers?
#decompile #ReverseEngineering
Decompiler Explorer is an interactive online decompiler which shows equivalent C-like output of decompiled programs from many popular decompilers.Decompiler Explorer
A secret, religious arbitration between two Israeli businessmen reveals that they had 'invested' as much as $25 million in President Enrique Peña Nieto of Mexico.Gur Megiddo (Haaretz)
EscapeVelocity reshared this.
This open-webui extension looks needful
openwebui.com/t/gatovillano/ne…
Nextcloud Integration v0.3 Tool • Open WebUI Community - With this tool, you can access your Nextcloud, list your calendars, create events, and review your files. It's an early experiment.openwebui.com
EscapeVelocity reshared this.
AOC Is A Genocidal Con Artist
Saying you support funding Israel's "defensive weapons" while opposing sending it "offensive weapons" is as nonsensical as saying you would never give a mass shooter guns and ammunition, but you would give him body armor to keep him safe from the police.
caitlinjohnst.one/p/aoc-is-a-g…
Listen to a reading of this article (reading by Tim Foley):Caitlin Johnstone (Caitlin’s Newsletter)
U.S. rejects amended WHO health regulations-english.news.cn
Memory cafes at the National Comedy Center ignite laughter and connection for dementia patients
https://apnews.com/article/national-comedy-center-alzheimers-memory-cafes-ad0ea8d6f42dc815917b2e72cf6a7bde?utm_source=flipboard&utm_medium=activitypub
Posted into U.S. News @u-s-news-AssociatedPress
Experience the heartfelt emotion of Avril Lavigne's "When You're Gone," a touching ballad from her album "The Best Damn Thing." This poignant track beautifully captures the feelings of loss and longing, showcasing Avril's powerful vocals and songwriting talent. Dive into the depth of this song that resonates with anyone who has experienced separation.
Follow Avril Lavigne:
► Follow Avril Ramona Lavigne: @avrillavigne@tube.matrix.rocks
► Watch more music videos by Avril Lavigne: tube.matrix.rocks/c/avrillavig…
► Listen to Avril Lavigne: tube.matrix.rocks/a/avril_lavi…
► Listen to Avril Lavigne's "The Best Damn Thing (Deluxe Version)": tube.matrix.rocks/w/p/tpcmmh5h…
► Subscribe to the official Avril Lavigne channel: tube.matrix.rocks/c/avrillavig…
🎵 L Y R I C S 🎵:
I always needed time on my own
I never thought I'd need you there when I cry
And the days feel like years when I'm alone
And the bed where you lie is made up on your side
When you walk away, I count the steps that you take
Do you see how much I need you right now?
When you're gone, the pieces of my heart are missing you
When you're gone, the face I came to know is missing too
When you're gone, the words I need to hear
To always get me through the day
And make it okay
I miss you
I've never felt this way before
Everything that I do reminds me of you
And the clothes you left, they lie on the floor
And they smell just like you
I love the things that you do
When you walk away, I count the steps that you take
Do you see how much I need you right now?
When you're gone, the pieces of my heart are missing you
When you're gone, the face I came to know is missing too
And when you're gone, the words I need to hear
To always get me through the day
And make it okay
I miss you
We were made for each other
Out here forever
I know we were, yeah-yeah
And all I ever wanted was for you to know
Everything I do, I give my heart and soul
I can hardly breathe, I need to feel you here with me, yeah
When you're gone, the pieces of my heart are missing you
When you're gone, the face I came to know is missing too
When you're gone, the words I need to hear
Will always get me through the day
And make it okay
I miss you, mmm
Album Artist: Avril Ramona Lavigne
Album(s): The Best Damn Thing
Written by: Avril Lavigne, Butch Walker
Music genre(s): Pop, Rock
Released: 2007
Decade for first release: #2000sMusic
#AvrilRamonaLavigne #AvrilLavigne #TheBestDamnThing #WhenYoureGone #Pop #Rock #2000sMusic #loveSongs #femaleMusicians #femaleVocalist
Get ready to turn up the heat with Avril Lavigne's "Hot," a vibrant anthem from her album "The Best Damn Thing." This energetic track showcases Avril's playful side and catchy pop-rock sound, making it a fan favourite. Dive into the fun and excitement of this song that perfectly captures the essence of youthful exuberance.
Follow Avril Lavigne:
► Follow Avril Ramona Lavigne: @avrillavigne@tube.matrix.rocks
► Watch more music videos by Avril Lavigne: tube.matrix.rocks/c/avrillavig…
► Listen to Avril Lavigne: tube.matrix.rocks/a/avril_lavi…
► Listen to Avril Lavigne's "Avril Lavigne (Expanded Edition)": tube.matrix.rocks/w/p/pJ7A6HGX…
► Subscribe to the official Avril Lavigne channel: tube.matrix.rocks/c/avrillavig…
🎵 L Y R I C S 🎵:
Oh, oh, oh
You're so good to me baby, baby
I wanna lock you up in my closet
When no one's around
I wanna put your hand in my pocket
Because you're allowed
I wanna drive you into the corner
And kiss you without a sound
I wanna stay this way forever
I'll say it loud
Now you're in, and you can't get out
You make me so hot
Make me wanna drop
It's so ridiculous
I can barely stop
I can hardly breathe
You make me wanna scream
You're so fabulous
You're so good to me baby, baby
You're so good to me baby, baby
I can make you feel all better
Just take it in
And I can show you all the places
You've never been
And I can make you say everything
That you've never said
And I will let you do anything
Again and again
Now you're in, and you can't get out
You make me so hot
Make me wanna drop
It's so ridiculous
I can barely stop
I can hardly breathe
You make me wanna scream
You're so fabulous
You're so good to me baby, baby
You're so good to me baby, baby
Kiss me gently
Always I know
Hold me, love me
Don't ever go
Oh, yeah yeah
You make me so hot
Make me wanna drop
You're so ridiculous
I can barely stop
I can hardly breathe
You make me wanna scream
You're so fabulous
You're so good to me
You make me so hot
Make me wanna drop
You're so ridiculous
I can barely stop
I can hardly breathe
You make me wanna scream
You're so fabulous
You're so good to me baby, baby
You're so good to me baby, baby
You're so good
Album Artist: Avril Ramona Lavigne
Album(s): The Best Damn Thing
Written by: Avril Lavigne, Evan Taubenfeld
Music genre(s): Pop, Rock
Released: 2007
Decade for first release: #2000sMusic
#AvrilRamonaLavigne #AvrilLavigne #TheBestDamnThing #Hot #Pop #Rock #2000sMusic #femaleMusicians #femaleVocalist
Isaac Scott--Listen to the Blues:
youtube.com/watch?v=Mq4e0wPWpE…
Provided to YouTube by The Orchard EnterprisesListen To The Blues · Isaac ScottBig Time Blues Man℗ 2006 Red Lightnin RecordsReleased on: 2006-12-12Auto-gener...YouTube
Little Milton--Right to Sing the Blues:
youtube.com/watch?v=QupX7-4AcQ…
Provided to YouTube by Malaco RecordsA Right To Sing The Blues · Little MiltonReality℗ 1991 Malaco Records, Inc.Released on: 1991-06-20Contributor: Milton Ca...YouTube
Vanessa Beeley- Syria's Fall Into Israeli Hands, US-Zionist Entity Targets Hezbollah, Abraham Shields Forges On, Trump's Big Beautiful Bill Points To War With Iran, Russia, China & Warrantless Surveilthealtworld (TheAltWorld’s Newsletter)
S-A-T-U-R-D-A-Y NIGHT!!!!
Official HD Video for "I'm With You" by Avril Lavigne
Follow Avril Lavigne:
- Fediverse: tube.matrix.rocks/a/avril_lavi… @avrillavigne@tube.matrix.rocks
Lyrics:
I'm standing on the bridge
I'm waiting in the dark
I thought that you'd be here by now
There's nothing but the rain
No footsteps on the ground
I'm listening but there's no sound
Isn't anyone trying to find me?
Won't somebody come take me home?
It's a damn cold night
Tryin' to figure out this life
Won't you take me by the hand
Take me somewhere new?
I don't know who you are, but I
I'm with you
I'm with you, mm
I'm looking for a place
I'm searching for a face
Is anybody here I know?
'Cause nothing's going right
And everything's a mess
And no one likes to be alone
Isn't anyone trying to find me?
Won't somebody come take me home?
It's a damn cold night
Trying to figure out this life
Won't you take me by the hand
Take me somewhere new?
I don't know who you are, but I
I'm with you
I'm with you, yeah-yeah
Oh, why is everything so confusing?
Maybe I'm just out of my mind
Yeah-yeah-yeah, yeah-yeah
Yeah-yeah, yeah-yeah, yeah
It's a damn cold night
Trying to figure out this life
Won't you take me by the hand
Take me somewhere new?
I don't know who you are, but I
I'm with you
I'm with you
Take me by the hand
Take me somewhere new
I don't know who you are, but I
I'm with you
I'm with you
Take me by the hand
Take me somewhere new
I don't know who you are, but I
I'm with you, oh
I'm with you
I'm with you
Written by: #Graham #Edwards, #Lauren #Christy, #Avril #Ramona #Lavigne, #David #Scott #Alspach
Album: Let Go
Released: #2002
#AvrilLavigne #AvrilRamonaLavigne #googleFree #youtubeFree #lyrics #musicVideo #popMusic #rockMusic #music #alternativeRock #femaleMusic #femaleMusicians #femaleMusician #femaleSinger #femaleVocalist #OfficialVideo #OfficialAudio #LetGo #ImWithYou
Avril Ramona Lavigne is a Canadian singer-songwriter. Body shape: Banana Dress size (US): 2 Breasts-Waist-Hips: 86-60-86 cm (34-24-34 inches) Shoe size (US): 7 Bra size: 32B Cup size (US): B Heig...Music Videos and Funny clips
TEHRAN, Jul. 19 (MNA) – Yemen’s military says it successfully targeted Israel’s Ben Gurion Airport with a hypersonic “Palestine-2” missile, prompting mass evacuations and flight suspensions.Mehr News Agency
#palestine #gaza #rafah #freepalestine
abc.net.au/news/2025-07-20/isr…
ABC News provides the latest news and headlines in Australia and around the world.ABC News (Australian Broadcasting Corporation)
I'm going to hold your hand when I say this. I don't give a fuck whether immigrants "came here literally" or not.
We live in a country run by billionaire pedos who are actively burning the planet to the ground for a few more dollars and pulling us all down into actual fucking fascism but somehow I'm supposed to care about Juan the gardener and his wife Maria who makes the absolute best fucking homemade empanadas I've ever eaten in my life and whether they filed form M-725-E before or after crossing an imaginary line in the sand?
Ok weirdo.
#mpox #health #qldpol #qldgov #qld #queensland #australia #ausgov #auspol #tasgov #taspol #politas
abc.net.au/news/2025-07-20/sec…
ABC News provides the latest news and headlines in Australia and around the world.Ned Hammond (Australian Broadcasting Corporation)
Creedence Clearwater Revival--Born on the Bayou:
youtube.com/watch?v=fcTQCNntGE…
Join the official CCR email list: http://found.ee/CCR_NewsletterMusic video by Creedence Clearwater Revival performing Born On The Bayou. (C) 2012 Concord Mu...YouTube
reshared this
Pars Today – The Ambassador of the Islamic Republic of Iran to China has stated that Iran's active diplomacy is moving forward with a powerful strategic ap...Pars Today
Turns out, pigs can fly.
What is it with LA cops and blowing up the neighborhood?
bbc.com/news/articles/c62891d4…
Federal agents are investigating, but authorities describe it as "an isolated incident" with no further threat to the public.Nadine Yousif (BBC News)
Free Mario Guevara!
atlantaciviccircle.org/2025/06…
#MarioGuevara #antiICE #Atlanta #Chamblee #fuckICE
Learn about Mario Guevara, the journalist arrested during an anti-ICE protest while covering the event for the community.Alessandro Marazzi Sassoon (Atlanta Civic Circle)
If you only read one article today, make it this one.
Excerpt: The biggest problem with removing evil from American culture and what’s left of our civilization is, quite frankly, the Democratic Party. Their mantra calls evil good, and good evil, and it is imperative, for them, that they have as much human depravity as possible. That is the source of their political power.
townhall.com/columnists/markle…
They are lying about everything. They are lying about climate change. They are lying about the Epstein files. They are...Mark Lewis (Townhall)
HeyLiberty 🗽🇺🇸 MAGA Bloodbath🩸 reshared this.
reshared this
More your style
Make sure to download Opera for free using my link: https://opr.as/Opera-browser-mattstonieVideo sponsored by: OpreaWe tasted & ranked Every Single Gordon Ra...YouTube
US President Donald Trump sues the Wall Street Journal for $10 billion over its reporting on a 2003 birthday letter that Trump allegedly sent to Jeffrey Epstein.Al Mayadeen English (Trump sues WSJ for $10bln over Epstein birthday letter report)
Grisham's tiebreaking slam in 9th completes Yankees comeback against Braves
https://apnews.com/article/yankees-braves-score-grisham-volpe-356b33d6a4e3fe1b4f58a0c3bd32e376?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
Link to play: https://gamaverse.com/underwheels-game/Underwheels is a parody game based on the Asgore meme. Get behind the wheel as Asgore Dreemurr himself a...YouTube
reshared this
3 people are still missing from deadly July 4 floods in Texas county, down from nearly 100
https://apnews.com/article/texas-floods-kerrville-missing-people-60879abd90bddf83e81af0e436afc33d?utm_source=flipboard&utm_medium=activitypub
Posted into U.S. News @u-s-news-AssociatedPress
Jazzilla reshared this.
John Oliver's Erie Moon Mammoths debut in front of a record crowd
https://apnews.com/article/john-oliver-erie-moon-mammoths-8909814abd7f3c6e9768200e858515cf?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
WNBA All-Stars make statement with warmup shirts over CBA
https://apnews.com/article/allstar-game-cba-7d122d2e895b7a60926299a78498ebc8?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
Paultron-3030 likes this.
Science shouldn’t be a partisan issue.
From cancer treatments to extreme weather alerts, science makes everyone’s life better, regardless of political affiliation.
But science becomes partisan when corrupt politicians defund research, fire scientists, and censor data, harming us all.
Regardless of political affiliation, yes.
But not regardless of wealth.
Current Science seems to say that the extreme wealth concentration is bad for society, economy and the environment.
So the extremely wealthy want to destroy science.
Over a year ago, I posited that AI coding stuff isn't about coding or productivity. It's about some % of people who feel a stimulus-reward thing from using it, similar to how some people feel when gambling. It feels so overwhelmingly good to some % of people they don't even bother to measure if their AI stuff is actually doing anything useful, because of course it must be, because the feeling is so strong.
It seems more & more people are also finding this idea lately.
But I've also realized that it seems to apply to any of the prompt-style AI things, not just coding. There is some kind of slot machine playing mania (sorta, not exactly) thing it triggers in some % of people. I'm certain of it now.
If anything, it makes me feel a bit less angry and more sad towards the people with this AI prompt-query compulsion. It feels closer to when you see someone with a gambling addiction stuck at a gambling machine.
this reflects my experience pretty strongly.
I've been pretty staunchly opposed to this wave of gen-AI since chatGPT launched in 2022, and never intentionally touched it until three months ago, when I finally felt like I needed to spend at least a little bit of time with it to understand/prove what I was opposed to. it almost *immediately* triggered an addiction response (of the gambling category, as you pointed out), to the point where within a week I could barely sleep, and all I could think about was prompting, explicitly like I needed to be using it 24/7 and trying to figure out the right way to extract quality output from it, under this sudden manufactured feeling of urgency.
luckily, i got burnt out on it pretty "quickly" (roughly a month) which forced me to step back, and had lived long enough to be able to identify what this cycle was. It was also tremendously helpful to both have had a long critical perspective built against the tech that I had now tested against, and a really high bar of personal work quality that I was able to use to categorize that output of these tools as "complete shit".
it's wild to me that as someone who was pretty publicly and vocally against the principle of the tech, this addiction loop still hit me at full force, on the very first prompt I ever fed it. for people without the life experience, critical lens, and body of high quality personal work to measure against, I can't imagine how many could possibly escape from the slot machine cycle. "if I can just figure out exactly how to word this prompt, it'll solve all my problems...". I wonder how those who do escape don't talk about it publicly out of shame (me, until this post).
the silver lining for me personally is that it did end up having some kind of positive effect on how I approach my work. reading through so much slop for a month re-lit a fire within me to be even more intentional and human in my work, whether through writing or code.
Holy shit. Okay, that's terrifying.
Me, I have next to no susceptibility to gambling-- for one thing, I understand too much about math, the odds of winning are so low the whole thing strikes me as contemptibly absurd-- and for another, I'm a digital artist so gut-wrenched by the uncanny valley effect of putting other people's work through a meat grinder and regurgitating it into a shambling frankenitation of art that it makes me feel physically ill, so I haven't even touched it. I've just been sitting here mystified like WHY EVEN...
If that's the type of effect it's having on people who aren't wired like me... good gawd, we're in deep shit.
Japan votes in a key election as Prime Minsiter Ishiba faces a loss and political uncertainty
https://apnews.com/article/japan-politics-election-ishiba-parliament-vote-fcc2fb4cce609240d1c2369bf4090e26?utm_source=flipboard&utm_medium=activitypub
Posted into Asia @asia-AssociatedPress
Sensitive content
pal likes this.
Venezuela and Colombia formalized a joint Peace and Economic Zone to promote cross-border development and integration.teleSURenglish
Napheesa Collier's record-breaking performance leads her team to victory in WNBA All-Star Game
https://apnews.com/article/wnba-all-star-clark-collier-9106a268000a103447b06f727af57afa?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
Giant defense contractors like Lockheed Martin are angling for a piece of President Trump's "Golden Dome" funding. Cenk Uygur and Ana Kasparian discuss on Th...YouTube
EscapeVelocity reshared this.
@ryan
This man loves the smell of diversity
RT: social.binarydad.com/users/rya…
💬 0 🔁 15 ❤️ 49 · Saw this brought up on Twitter but no, women aren't emotionally free. Women are not totally free to express their emotions unlike cis guys. They accused women of "Hysteria" an…Tumblr
Ill go to a Mom n Pop joint like Ye Olde Fashioned Ice Cream Shoppe or Cookout Burger or Wendy's usually for a burger on the go.
Gaza today is not merely a geographic flashpoint or a humanitarian crisis. It stands as a profound symbol of the moral cenglish.pnn.ps
Haitian Illegal Alien Arrested in Massachusetts for Raping and Impregnating His 14-Year-Old Daughter
thegatewaypundit.com/2025/07/h…
A Haitian illegal alien has been arrested in Massachusetts for raping and impregnating his 14-year-old daughter.Cassandra MacDonald (Where Hope Finally Made a Comeback)
HaraldvonBlauzahn
in reply to HaraldvonBlauzahn • • •The details are complex; it has humorously been called "security by security".
Hobby Linux users could, as far as I understand , simply disable UEFI secure boot (after weigthing carefully what secure boot provides to them, and what it does not provide). Otherwise, they'll need a firmware upgrade before any upgrade to a new OS / bootloader chain.
Small companies which use old laptops with Windows might be bitten hard by this because they can become locked out of their hardware with no way to update it, or even make a backup!
specification that defines a software interface between an operating system and platform firmware
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)HaraldvonBlauzahn
in reply to HaraldvonBlauzahn • • •(Nearly) All Your Computers Run MINIX
HackadayTechnus
in reply to HaraldvonBlauzahn • • •For a home desktop that's never left unattended with anyone untrustworthy, I don't see that Secure Boot is worth the effort in setting up.
Given that you have to re-sign the boot image every time you upgrade, any malware already running with root privileges on the machine could easily slip itself into the new signed image.
The best security is not running untrusted software to begin with.
HaraldvonBlauzahn
in reply to Technus • • •Can you explain the detailed reason why you think that? Voicing opinions is nice of course but explaining the thought process and logic is, I think, almost always more interesting to other people.
To start with, what do you think is the "normal users" threath model? And, for example, if one happens to be a member of any of the various minorities that authoritarian governments of every color happen to single out and persecute in your countries case, what would you want to protect from? Or if you are, say, a lawyer, and have a professional obligation to protect sensitive data from theft?
Technus
in reply to HaraldvonBlauzahn • • •Actually, I would love for you to explain to me how Secure Boot alone would protect someone from any of that. If you want to protect files, you need full disk encryption, not Secure Boot.
Or are you seriously expecting a government-level threat actor to bother to:
That's the great thing about fascist governments, is they have no need to be that sneaky. They can just change the laws to make whatever you're doing illegal and jail you until you agree to give up your documents, or simply hit you with a $5 wrench until you tell them the password.
Security
xkcdbalsoft
in reply to HaraldvonBlauzahn • • •Secure Boot is a really contrived and, frankly, bad defense against an attack that is extremely difficult to execute in reality and does not happen often (are there any examples of a bootloader replacement against a home desktop in the wild?).
An actually good solution would be firmware support for LUKS-style FDE (with a password-encrypted key which then encrypts the rest of the disk), so that your bootloader is encrypted with the rest of your system and impossible to substitute without erasing the rest of the disk, until you enter the password. This way there's no need for key enrolment into firmware, and firmware manufacturers don't have to just trust MS. (the firmware of course needs to be protected too, by signing it with the manufacturer's key; if you flash something unsigned, a warning pops up Android-style before every boot).
If you are hiding something from the state (like your sexual orientation or something), your energy is much better spent encrypting your communications online and keeping your identities anonymous. If you are already suspicious enough to try and pull a bootloader replacement attack on you, any authoritarian state which would do that in the first place will just throw you in jail and fabricate evidence as needed.
SheeEttin
in reply to Technus • • •If secure boot is off, and you run malware on your pc, it can change the boot process to escalate privileges.
This probably requires root or admin in the first place, but if they can install a malware loader, they can establish persistence so that even if you remove the os-level components, they'll be reinstalled on reboot.
Technus
in reply to SheeEttin • • •Yeah, but the malware can just wait for a system upgrade where you sign a new boot image and slip itself in then.
It works for Windows because theoretically only Microsoft would have the signing key and it's not just sitting on disk somewhere. But then you're just trusting Microsoft, and also subject to vendor lock-in.
HaraldvonBlauzahn
in reply to SheeEttin • • •This is technically correct, but on a desktop system, malware executing in user space is normally already game over. It can exfiltrate and send your passwords or ssh private keys, change browser certificates or browser software, add user systemd sessions or crontab entries and can generally e.g. do everything a banking trojan would like to do.
Max-P
in reply to HaraldvonBlauzahn • • •As commenters on the LWN thread said, I doubt that many firmwares even bother to check anyway. My motherboard happens to have had a bug where you can corrupt the RTC and end up in 2031 if you overclock it wrong. I didn't use secure boot then though so I don't know if it would have still booted Windows. But I imagine it would.
That said, I've always just enrolled my own keys. I know some other distros that make you enroll their keys as well like Bazzite. At least that way you don't depend on Microsoft's keys and shim or anything, clean proper secure boot straight into UKI.
HaraldvonBlauzahn
in reply to Max-P • • •Seems it compares the expiration date of the UEFI key with the signature date of the bootloader / OS keys. (See the comments on the LWN article, some are far more knowledgeable than I am.) So, no, it does not require a working on-board clock to lock you out if you are not extremely careful and fully understand each part.
HaraldvonBlauzahn
in reply to Max-P • • •That does not help if the master key in the key chain is expired.
Sure you can disable Secure Boot. But a password-protected BIOS is secured by TPM again. High levels of security always carry a risk of locking oneself out.
don't like this
Mark doesn't like this.
exu
in reply to HaraldvonBlauzahn • • •I don't think you understand what "enrolling your own keys" means in the context of Secure Boot.
The key affected here is specifically for the Linux shim signed by Microsoft. It is used by GRUB and some distros to work with Secure Boot.
Enrolling your own key means you add a new certificate to the key store. This is completely separate from the one provided by Microsoft and controlled only by you. The common recommendation is to remove all built-in keys and only add your own, to make this system as secure as possible.
like this
Mark likes this.
HaraldvonBlauzahn
in reply to exu • • •And exactly that Linux shim signed by Microsoft is no longer valid because the Microsoft signature in the UEFI firmware is expired.
HaraldvonBlauzahn
in reply to exu • • •OK, now you are talking about something a bit different - registering own keys in the UEFI system, which is significantly more involved than updating the BIOS, and also requires firmware support, and the firmware also needs to match the motherboard. And the whole issue with ACPI support for Linux shows clearly that having reams of specufications is not enough, the implementation of the BIOS needs to match that specification which whether thsz's the case you will only learn after you bought the hardware.
Here is a description of that process:
docs.bell-sw.com/alpaquita-lin…
Moreover, for any change of the boot chain, bootloader, posdibly also kernel, this needs to be repeated.
Do you think that's accessible to normal users? Considering most have probably not even ever done a firmware update?
Using Your Own Keys in Secure Boot
docs.bell-sw.comexu
in reply to HaraldvonBlauzahn • • •From the first post in this chain
I didn't start talking about it, this was many comments above
HaraldvonBlauzahn
in reply to Max-P • • •The whole point of the article is that you do depend on their expired root key. You have produced a lot of text without even understanding the key issue. At that point I am wondering whether all that text was produced by an LLM?
don't like this
Mark doesn't like this.
Norah (pup/it/she)
in reply to HaraldvonBlauzahn • • •HaraldvonBlauzahn
in reply to Norah (pup/it/she) • • •Please don't troll and come back to the topic. GP was completely missing the topic, do you want to avoid it?
Um, given that Secure Boot prevents any modification of your computer's boot chain - including installing another boot loader or OS - that's not how it works.
don't like this
Mark doesn't like this.
Norah (pup/it/she)
in reply to HaraldvonBlauzahn • • •like this
Mark likes this.
Max-P
in reply to HaraldvonBlauzahn • • •That's the whole point of enrolling your own keys in the firmware. You can even wipe the Microsoft keys if you want. You do that from the firmware setup, or within any OS while secure boot is off (such as
sbctl
on Linux).That's a feature that is explicitly part of the spec. The expectation is you password protect the BIOS to make sure unauthorized users can't just wipe your keys. But also most importantly that's all measured by the TPM so the OS knows the boot chain is bad and can bail, and the TPM also won't unwrap BitLocker/LUKS keys either.
Secure boot is to prevent unauthorized tampering of the boot chain. It doesn't enforce that the computer will only ever boot Microsoft-approved software, that's a massive liability for an antitrust lawsuit.
HaraldvonBlauzahn
in reply to Max-P • • •That is far more complex than a firmware update and also depends on a correct implementation of the spec in the BIOS - which, given the experiences with ACPI for Linux, is not at all something one can rely on.
Max-P
in reply to HaraldvonBlauzahn • • •HaraldvonBlauzahn
in reply to Max-P • • •ACPI modules - ArchWiki
wiki.archlinux.orgEugenia
in reply to HaraldvonBlauzahn • • •Tenderizer78
in reply to Eugenia • • •I just tried to distro-hop and found my BIOS had been locked with a password. Assuming I didn't set a password that I subsequently forgot (and that isn't one of the many I have memorized), I figured this might have something to do with the age of the laptop (I have a HP 4540s). If certificate expiration is already affecting people then this might be it.
EDIT: I just forgot I set a password, and it took me 2 days to realize that I was stupid enough to have set the password that I used for everything when I was 12 years old.
drspod
in reply to Tenderizer78 • • •Tenderizer78
in reply to drspod • • •deadcatbounce
in reply to HaraldvonBlauzahn • • •Being beholden to Microsoft doesn't sound like something anyone needs.
Until that ends I'm doing best to avoid secure boot. I don't want to.
data1701d (He/Him)
in reply to deadcatbounce • • •deadcatbounce
in reply to data1701d (He/Him) • • •I thought it was a Microsoft centric thing in that the certificate authority was either Microsoft or signed by Microsoft?
Maybe I need to read about it more? Can you direct me to the general area?
WhyJiffie
in reply to deadcatbounce • • •Microsoft's keys are pre-installed to all motherboards, so boot binaries signed by Microsoft are trusted by default. afaik Microsoft keys often can't be removed, but not because it's not possible, but because it can brick devices. you can create your own MOK or Machine Owner Keys and set up your linux system to sign your bootloader and kernel with it, but that is in addition to Microsoft keys.
wiki.archlinux.org/title/Unifi…
Unified Extensible Firmware Interface/Secure Boot - ArchWiki
wiki.archlinux.orgdeadcatbounce
in reply to WhyJiffie • • •Thank-you. Recently rebuilt my Arch Rescue build and saw that section in doing the UKI dance.
I don't mind the Microsoft keys being there at all. I just don't think tying myself to them is particularly clever.
From your final part. I think I need to go back and reread it. Thank-you again.
☂️-
in reply to data1701d (He/Him) • • •HaraldvonBlauzahn
in reply to ☂️- • • •Max-P
in reply to HaraldvonBlauzahn • • •That's bullshit. ARM is an architecture and by itself does not specify secure boot any more than x86 does. Raspberry Pis don't have secure boot. You can unlock the bootloader on a Pixel, install GrapheneOS, and relock the bootloader just fine. Several other manufacturers allow bootloader unlocks no problem. The main reason you can't on some popular phones is US carriers, even international Samsungs you can unlock the bootloader and flash whatever you want on it.
I'm literally typing this comment on a phone running a custom OS (LineageOS on a OnePlus 8T). I'm literally 2 versions of Android ahead of the latest supported version. I also have a Galaxy S7 running Android 15, a phone that officially tops out at Android 8 and launched with Android 6. Both you literally just toggle the bootloader unlock option in the settings, no hacks no craziness, it's literally a feature.
At this point you're just straight up making shit up.
HaraldvonBlauzahn
in reply to Max-P • • •I mean Windows PCs with ARM CPUs which have Secure Boot, not Android smart phones or embedded devices.
Max-P
in reply to HaraldvonBlauzahn • • •Nope. Even Qualcomm themselves provide what's needed to run Linux on the Windows for ARM PCs.
The only one I can't find for sure is whether there's any lockdown on the firmware for the Microsoft Surface and Copilot+ laptops, but I'm also not finding any sources pointing that it would be. But at this point you're buying Microsoft hardware, what do you expect.
Qualcomm Snapdragon X Elite Benchmarks On Ubuntu Linux vs. AMD vs. Intel
www.phoronix.comHaraldvonBlauzahn
in reply to deadcatbounce • • •Here
en.m.wikipedia.org/wiki/UEFI#S…
is a list of problems and criticism on Secure Boot.
specification that defines a software interface between an operating system and platform firmware
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)deadcatbounce
in reply to HaraldvonBlauzahn • • •xia
in reply to HaraldvonBlauzahn • • •☂️-
in reply to xia • • •HaraldvonBlauzahn
in reply to ☂️- • • •There is even a whole section in Wikipedia on issues and criticism with secure boot:
en.m.wikipedia.org/wiki/UEFI#S…
Some people argue that one can work around such locking down of PC hardware. Do this or that to avoid issues with substantial tinkering.
But that is not a bug but a feature. Sure, as a technical Linux user you can work around some nastiness. Like working around privacy invasion on Facebook or Linkedin by "adjusting" settings, or "adjust" settings in Wimdows to make it more private and so on. The thing is: working against the platform becomes quickly a losing game, because you don't control the platform - Microsoft does. And it does not help you if you manage to re-gain control of your device after some hours of tinkering if 99.9% of people around you don't have the knowledge and time and store your data, photos, Emails on OneDrive and so on. Freedom is very much a collective thing and software freedom is no exception.
And this does not mean that the thinkering and hacking is in vain - but it is not enough. We need the practical right to control our devices.
specification that defines a software interface between an operating system and platform firmware
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)☂️-
in reply to HaraldvonBlauzahn • • •Decker108
in reply to HaraldvonBlauzahn • • •