this post was submitted on 23 Jul 2025
90 points (94.1% liked)

Linux

8623 readers
694 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Ooops@feddit.org 18 points 4 days ago

The actual problem is (and has been for a long time) the enormous amount of absolute trash-level uefi implementations.

Updating keys is easy. Alas... a lot of them are completely broken beyond repair and fail everything but running with the pre-installed keys, which includes updating (or adding new) keys (bonus points for the really screwed up devices that even sign some their own hardware with the pre-installed MS keys thus bricking themselves if those keys are changed).