46
submitted 11 months ago by cm0002@piefed.world to c/privacy@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] RedGreenBlue@lemmy.zip 4 points 11 months ago* (last edited 11 months ago)

The manufacturer puts a key on the chip in your computer. Currently controlled by microsoft. The software you boot is checked against these keys and if they don't check out, it will refuse to boot. In theory this means you can't modify the software that is booting. Only microsoft can sign approved code. This includes malware sneakily loading together with the operating system, embeding itself on a low level, with all permissions.

[-] wildbus8979@sh.itjust.works 6 points 11 months ago

I think it's important to add some nuance to what you said. While it's true that computers ship with Microsoft keys. One can remove them and install their own. I run all my machines with self signed bootloaders/kernels and it works great!

this post was submitted on 13 Sep 2025
46 points (97.9% liked)

Privacy

5093 readers
35 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS