#SecureBoot

2025-12-06

Fix Secure Boot State Unsupported in Minutes

Getting the “Secure Boot State Unsupported” warning on Windows 10/11? Here’s a simple guide to turn it around fast and get your PC upgrade-ready.

izoate.com/blog/6-proven-metho

Der Techniker 💎dertechniker
2025-12-05

Hallo @tuxedocomputers
besteht die Möglichkeit als Live-Image mit aktiviertem zu starten?
Danke für ein Tipp.

2025-12-02

Information about #SecureBoot and #VerifiedBoot on #Linux systems from the masters of boot, with plenty of diagrams for clarification -->
blog.3mdeb.com/2025/2025-07-18
@3mdeb

Mobile FOSS-friendly developers could be very helpful by creating a similar explanation about what is "open" and what is "closed," who gets what permissions where, what is proprietary, what is manufacturer controlled and what is owner controlled, etc, and compare #GrapheneOS to #PostMarketOS, #UbuntuTouch, iPhone, and Mobian. @debian

That someone could be me with enough time and effort since no one else seems to be doing it. But it would be quite the study and a comprehensive explanation would require extensive research. The AOSP (non/semi) closure issue remains unclear to many people.

Why can't people just have a good Linux phone with full read write permissions and control their own crypto keys as it the case for workstations?
@postmarketOS

2025-12-02

Qualcomm has detailed six high-priority vulnerabilities — including a critical secure boot flaw (CVE-2025-47372). Additional issues affect TZ Firmware, HLOS components, DSP, audio, and camera modules.

OEMs are receiving patches and users may need to check manufacturer timelines for deployment.
Follow us for more non-sensationalized security reporting.

Source: gbhackers.com/qualcomm-alerts-

#Infosec #Qualcomm #SecureBoot #FirmwareSecurity #ThreatIntel #TechNadu #CVEs #DeviceSecurity

Qualcomm Alerts Users to Critical Flaws That Compromise the Secure Boot Process

Today I discovered, that after a #BIOS upgrade, I must re-enroll the akmods key to succesfully load the #nvidia driver with #secureboot enabled.

#fedora #silverblue

When I was setting up my server again a few days ago, I chose btrfs instead of ZFS, because apparently ZFS + Secure Boot + Debian 13 is pain in the ass 😒

Anyway, it seems to work great with btrfs so far.

#Linux #Incus #Debian #Btrfs #ZFS #SecureBoot

2025-11-29

@indietechnews@ioc.exchange @GrapheneOS

Pros of mobile over desktop/tablet/laptop form factor -->

Physical security of your primary cpu and disk is enhanced by the kind of portability you can always keep in your pocket. No evil maid attacks with your (convergence?) daily driver always in sight. No bad usb (rubber ducky) attacks or untrusted peripherals.

#SecureBoot protections only necessary realistically in very narrow circumstances like border crossings or seizures.

#PhysicalSecurity #AEM #BadUSB #Mobile #Convergence #RFHardened

Morten LinderudFoxboron@chaos.social
2025-11-28

If I were to hold a #SecureBoot talk in the #Distributions devroom at #FOSDEM.
What would you like to know?

2025-11-20

Grafikkarte verzögert Bootvorgang

Seit in meinen PC eine Grafikkarte vom Typ GeForce GT 710 läuft, dauert der Bootvorgang zum Windows-11-Logon über 40 Sekunden. Haben Sie eine Lösung?

heise.de/ratgeber/Grafikkarte-

#BIOS #PC #Grafikkarten #IT #SecureBoot #news

2025-11-19

Hey Linux Users,

Secure Boot on or off?

#Linux #SecureBoot

N-gated Hacker Newsngate
2025-11-15

👨‍💻🔧 Wow, a tech revelation: Linux actually works on a laptop! 🥳🎉 Who could have guessed? Secure Boot was the only hiccup—shocking! It's almost as if someone hadn't invented Google yet. 😂🔍
borretti.me/article/linux-on-t

Ludovic Poujollpoujol@mamot.fr
2025-11-11

Eh…

Keeping SecureBoot enabled, but no hibernation (even if... the swap file is on the encrypted system part) and no S3 sleep (because I need to override ACPI tables :s)

Or, disabling SecureBoot, and enjoying S3 sleep (saving energy) and having hibernation…

I guess my choice is done :v

(Laptop is a refurbished X1 Tabled 3rd gen)

#Debian #Laptop #SecureBoot

2025-11-09
#Incus impressed me as a #Proxmox alternative, but #IncusOS? That’s the next evolution!

IncusOS comes with all the missing things like ARM64 (aarch64) support, boot safety, full disk encryption, immutable images (read-only and signed) and fully locked down to operate in API only mode.

For me, it’s a mix of #Talos, #Harvester and Proxmox where it merges the best features of all ones!

Tags: #PVE #Virtualization #Containerization #Container #Containers #Linux #Debian #ARM64 #aarch64 #opensource #security #immutable #foss #LXC #LXD #VM #VPS #Immutable #secureboot #TPM

Blog post: https://gyptazy.com/incusos-a-platform-for-modern-virtualization-containerization-infrastructure/
IncusOS - Showing the Incus logo
Rosa Luxemburgo :Ryyca:RosaLuxemburgo@ursal.zone
2025-11-05

Alguém confirma?
Esse vídeo trouxe vários aspectos que eu não sabia sobre o uefi. Então eu posso produzir minhas próprias chaves?
#secureboot #linux #gnulinux #microsoft #openhardware #coreboot

Uma captura de tela de um post da plataforma de mídia social, do YouTube. O post contém um título acima de um vídeo e uma seção de comentários.

O título do post diz: “A maior VIGARICE da Microsoft com o Linux?” Abaixo do título, há informações sobre o canal “Diolinux” com 778 mil inscritos e o número de visualizações (104.758). Há ícones para adicionar à playlist, informações do vídeo e um botão de download.

A seção de comentários é destacada. O nome do usuário “[@]nw” é mostrado seguido pelo comentário: “A beleza do Secure Boot é exatamente não usar a CA da Microsoft. Senha forte na UEFI/BIOS, coloca o laptop/pc no secureboot em modo “user/custom”, faça deploy da sua própria CA, deixe a CA da Microsoft desabilitada(em algumas placas mae isso já acontece automaticamente depois do deploy), delete boot from pendrive e rede com o efibootmgr, instale seu Linux (no meu caso Arch) com LUKS e pronto. Se alguém roubar seu laptop o ladrão não consegue nem bootar um instalador do Windows from pendrive e pronto.”
Abaixo do comentário de [@]nw, há uma seção de curtidas com um número de 12 e um marcador de tempo de “1 semana atrás”.
Bradley M. Kühnbkuhn@copyleft.org
2025-11-04

I realized I should just make my sale easy on @novacustom, & signed up for an account on their forum.

They offered¹ to answer questions here, but I suspect Fediverse isn't a regular place they interact with users.

Here's the forum post that I just made about the #UEFI #SecureBoot question I had about the #NovaCustom:
novacustom.com/forum/d/595-uef
(Basically same question I asked above in this thread.)
I'll post again by replying to this post with links to useful answers.

¹ fedi.copyleft.org/@novacustom@

Bradley M. Kühnbkuhn@copyleft.org
2025-11-03

Re: #SecureBoot on @novacustom laptops:

1ˢᵗ,is all this right?:
* Heads—for users to “outsource” integrity & safety from “butler attack” to #NovaCustom/Dasharo
* TrustRoot is for enterprise customers who own the hardware & don't want employees tampering w/ its firmware

2ⁿᵈ, I want:
* Install my own UEFI keys.
* When #Dasharo recommends upgrade, I want to sign it too & upgrade only works w/ *BOTH* my & Dasharo's signatures.

Does “Yes—enable UEFI secure boot” put me on the path to do that?

From a secction entitled “Firmware options (Dasharo coreboot)” from the URL https://novacustom.com/product/v54-series/, it reads “The current Dasharo coreboot firmware options for advanced and firmware-interested people are listed here.”

The options listed are:

 * “Yes — enable UEFI secure boot” 
 * “Yes — keep me up to date about firmware updates.” 
 * “Yes — deploy coreboot+Heads (instead of coreboot+EDK-II” 
 * “Yes — disable the Intel Management Engine”
 * “Dasharo TrustRoot (Intel Boot Guard)”From a secction entitled “Firmware options (Dasharo coreboot)” from the URL https://novacustom.com/product/v54-series/, it reads “The current Dasharo coreboot firmware options for advanced and firmware-interested people are listed here.”

The image shows only one option (the rest being below where the screenshot was taken).  It is selected and reads “Yes — enable UEFI secure boot” It has a blue “?” that can be moused-over.From a secction entitled “Firmware options (Dasharo coreboot)” from the URL https://novacustom.com/product/v54-series/, it reads “The current Dasharo coreboot firmware options for advanced and firmware-interested people are listed here.”

The image shows only one option (the rest being below where the screenshot was taken).  A pop-up from mousing over a blue “?” covers the rest of screenshot, and the popup reads “UEFI secure boot ensures that only signed boot software is allowed to started.  This is done through certificates.  If no valid signature can be issued, the boot process will be blocked.”
Jörg 🇩🇪🇬🇧🇪🇺geco_de@troet.cafe
2025-11-01

@BjoernBeck Vielleicht kann jemand der diese Hastags findet helfen.

#linux #secureboot #followerpower #fedihelp

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst