Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.
Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.
I will just never bother with any of this Secure boot nonsense. I leave that bs to the windows users.
Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.
Sadly it is actually one of the biggest security features that modern computers have
What kind of attack does it actually protect against?
Rootkits
Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.