Skip to content

Comment on Lanzaboote – NixOS Secure Bootparent

Comments

Microsoft's certification states that OEM's must allow the user to configure secure boot to trust other bootloader's.

https://learn.microsoft.com/en-us/windows/security/operating...

However OEM's like HP are ignoring the certification requirements:

https://h30434.www3.hp.com/t5/Notebook-Operating-System-and-...

https://h30434.www3.hp.com/t5/Notebook-Boot-and-Lockup/How-t...

Interesting. I had a 705 G4 (or 74 g5? Idk the one with the Ryzen 2400Ge) and the firmware supported putting the machine secure boot system on setup mode.

Some cases OEMs ignore the requirement the other way round, e.g. the MSI boards that perform zero signature checking with secure boot on.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.