logoalt Hacker News

saidnooneevertoday at 7:02 AM2 repliesview on HN

it is stupid to turn it off. It is incredibly easy to infect your system components without your knowning.

that being said, it does assume a certain trust in firmware vendors / oems. If you dont trust those, then dont buy from them.

i think for most ppl trusting OEM or trusting rando from interwebz with a custom hypervisor and requirement to cripple my system security are totally different things ..

u know they could actually make theyr HV support secure boot etc. to do it properly and have ur system run the cracks but not have gaping holes left by them -_-. lazy.


Replies

maccardtoday at 7:33 AM

If you’re downloading torrents and running code with elevated privileges that infects your PC, 99% of people are absolutely hosed at that point anyway. I don’t see th real distinction between being owned at an elevated system level and owned by disabling system secure boot for a home user

show 1 reply
bandramitoday at 10:42 AM

As always in security, It Depends™; there are vulnerabilities that only impact systems with secure boot (and result in a situation worse than not having secure boot to begin with).

show 1 reply