this post was submitted on 07 Oct 2026
12 points (100.0% liked)

Linux and Tech News

3746 readers
87 users here now

This is where all the News about Linux and Linux adjacent things goes. We'll use some of the articles here for the show! You can watch or listen at:

You can also get involved at our forum here on Lemmy:

Or just get the most recent episode of the show here:

founded 3 years ago
MODERATORS
top 4 comments
sorted by: hot top controversial new old
[–] Ninguem@lemmy.pt 1 points 2 hours ago

As far as I can understand, only /boot has to be on a fat/ext4/iso9660 partition (apart from efi which has to be on a fat by itself). As efi is mounted on /boot/efi, I figure we'll need 2 separate partitions besides / (and whatever other partitions we might want to separate / into).

I start to worry that more and more of the system has to be uncovered to an attacker: if you keep the distro's kernel, it'll be easy to figure out the system installed on / so 90% of the data on disk will be known. No need for luks except for /home.

Is there a way to have whole disk encryption on linux and secure boot at the same time? efi already has to be unencrypted right? Now /boot...

Can systemd-boot save the day?

[–] eager_eagle@lemmy.world 8 points 3 days ago (1 children)

I don't understand what kind of problem/threat secure boot solves. Is that something useful to end users, or more of a corporative measure to protect their hardware running in untrusted environments?

[–] Strit@lemmy.linuxuserspace.show 9 points 3 days ago* (last edited 3 days ago) (1 children)

As I understand it, it's Microsofts attempt to only allow booting kernels signed by them or their partners. In theory this stops malicious attacks from changing the kernel and have it booted. But Secure Boot is just something you can turn off.

[–] adespoton@lemmy.ca 7 points 2 days ago

Not only that, earlier this year, it was discovered that there was a flaw in Secure Boot that meant it never even did the one thing it was supposed to do. This update is designed to make it functional for the first time.