<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=3970&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=3970</link>
		<description><![CDATA[The most recent posts in How to make devuan boot with Secure Boot enabled the way antiX does it.]]></description>
		<lastBuildDate>Fri, 04 Dec 2020 21:37:33 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26101#p26101</link>
			<description><![CDATA[<div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>why does my bios menu have a checkmark saying disable uefi / enable legacy bios</p></div></blockquote></div><p>The &quot;legacy bios&quot; [sic] is an emulation performed by the UEFI firmware.</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>Do you have you any historical examples of said rootkits?</p></div></blockquote></div><p>See <a href="https://www.blackhat.com/docs/asia-17/materials/asia-17-Matrosov-The-UEFI-Firmware-Rootkits-Myths-And-Reality.pdf" rel="nofollow">https://www.blackhat.com/docs/asia-17/m … eality.pdf</a> &amp; <a href="https://www.welivesecurity.com/wp-content/uploads/2018/09/ESET-LoJax.pdf" rel="nofollow">https://www.welivesecurity.com/wp-conte … -LoJax.pdf</a> (although Secure Boot doesn&#039;t actually offer any protection against LoJax).</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Fri, 04 Dec 2020 21:37:33 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26101#p26101</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26090#p26090</link>
			<description><![CDATA[<div class="quotebox"><cite>Ulysses_ wrote:</cite><blockquote><div><div class="quotebox"><blockquote><div><p>Ive not used antix or mx, i dont see the need for uefi boot or secure boot as mentioned by the limitations Head on a sticker mentions.</p></div></blockquote></div><p>It makes no sense that Microsoft would break what little security Secure Boot offers by allowing it to boot absolutely anything plugged into a usb port as long as it bothers to look live and EFI. Do you have any references for this unbelievable limitation?</p></div></blockquote></div><p>Hmm i dont understand your line of questioning. This is microsoft remember, the operating system that is prone to viruses, malware , constant bsod&#039;s and an update schedule that will from time to time brick your machine.</p>]]></description>
			<author><![CDATA[dummy@example.com (dice)]]></author>
			<pubDate>Fri, 04 Dec 2020 11:05:47 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26090#p26090</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26089#p26089</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>Ive just disabled uefi altogether</p></div></blockquote></div><p>No, you haven&#039;t. You&#039;ve enabled CSM (&quot;Legacy&quot; mode), which emulates non-UEFI booting via your machine&#039;s UEFI firmware. This means the machine is still open to the many UEFI firmware vulnerabilities.</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>my drives are encrypted so good luck to anyone who can get info off them</p></div></blockquote></div><p>If you have a rootkit then it can read the contents of the drive once the system is running. Secure Boot would help prevent rootkits from running. It&#039;s far from perfect but it is an extra layer of protection.</p><p>And before anybody starts bleating about not trusting Microsoft&#039;s keys note that it is possible to create your own keys, enrol them in the UEFI firmware and sign the kernel images with them. That&#039;s how I have enabled Secure Boot in my Alpine Linux system.</p></div></blockquote></div><p>Okay&#160; but why does my bios menu have a checkmark saying disable uefi / enable legacy bios, i suppose they are one in the same thing as you mention in regards to CSM? Ive not really delved into bios management before, im pretty sure i would brick the computer.I remember flashing a bios about 20 years ago on a windows 2000 machine, is that how it is still done and you just need the correct coreboot image for the machine?</p><p>Do you have you any historical examples of said rootkits?</p>]]></description>
			<author><![CDATA[dummy@example.com (dice)]]></author>
			<pubDate>Fri, 04 Dec 2020 11:02:39 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26089#p26089</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26088#p26088</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>Ive just disabled uefi altogether</p></div></blockquote></div><p>No, you haven&#039;t. You&#039;ve enabled CSM (&quot;Legacy&quot; mode), which emulates non-UEFI booting via your machine&#039;s UEFI firmware. This means the machine is still open to the many UEFI firmware vulnerabilities.</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>my drives are encrypted so good luck to anyone who can get info off them</p></div></blockquote></div><p>If you have a rootkit then it can read the contents of the drive once the system is running. Secure Boot would help prevent rootkits from running. It&#039;s far from perfect but it is an extra layer of protection.</p><p>And before anybody starts bleating about not trusting Microsoft&#039;s keys note that it is possible to create your own keys, enrol them in the UEFI firmware and sign the kernel images with them. That&#039;s how I have enabled Secure Boot in my Alpine Linux system.</p></div></blockquote></div><p>I myself prefer coreboot + intel me cleaner, or something equivalent of security, but good if you found a way around the issues of the stock bios. I just don&#039;t trust it myself man... </p><p>For that reason you mentioned and others, for example the intel me issue...</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Fri, 04 Dec 2020 06:58:13 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26088#p26088</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26087#p26087</link>
			<description><![CDATA[<div class="quotebox"><cite>Ulysses_ wrote:</cite><blockquote><div><div class="quotebox"><blockquote><div><p>seems foxnews like or far right or&#160; even extremist fringe of the far right ideology.</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>I wonder how coked up the op is.</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>he doesn&#039;t know what he&#039;s talking about.</p></div></blockquote></div><p>These are political remarks and insults to a member who is not allowed by golinux to reply to political remarks and defend their reputation. You are punching an opponent with his hands tied. You have been reported.</p></div></blockquote></div><p>I didn&#039;t know this, I am sorry, no one told me any of this. If I had known, I would have just told you to calm down in a peaceful manner. my apologies.</p><p>Please chill man, although I do still think you might be lost, I don&#039;t mean this in a harsh way,&#160; but rather that you have been misled.&#160; <img src="https://dev1galaxy.org/img/smilies/sad.png" width="15" height="15" alt="sad" /> </p><p>You would do wise to examine your own reality, I have to do that a lot myself. I am sure anyone who has an open mind has had to do the same.</p><p>That being said, I hold no ill will to&#160; you. I was only having fun before. I don&#039;t think you really do coke.&#160; Especially in the physical sense.</p><p>Peace...</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Fri, 04 Dec 2020 06:45:27 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26087#p26087</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26082#p26082</link>
			<description><![CDATA[<div class="quotebox"><cite>Ulysses_ wrote:</cite><blockquote><div><p>Who are the developers of devuan in this forum?</p></div></blockquote></div><p>I&#039;m one. I make the live isos and maintain a few packages. Why do you ask?</p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Thu, 03 Dec 2020 22:48:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26082#p26082</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26080#p26080</link>
			<description><![CDATA[<div class="quotebox"><cite>Ulysses_ wrote:</cite><blockquote><div><p>Alright. How do you feel about this?</p><div class="quotebox"><blockquote><div><p>Instead of answering the question that you know the answer to better than anyone</p></div></blockquote></div></div></blockquote></div><p>Can&#039;t really answer your question without context which starts with a citation for who posted it.&#160; Please include that when you quote in the future.</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Thu, 03 Dec 2020 22:46:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26080#p26080</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26078#p26078</link>
			<description><![CDATA[<p>Who are the developers of devuan in this forum?</p>]]></description>
			<author><![CDATA[dummy@example.com (Ulysses_)]]></author>
			<pubDate>Thu, 03 Dec 2020 20:43:21 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26078#p26078</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26077#p26077</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>we don&#039;t fork any of the packages necessary for secure boot. Make sure grub-efi-amd64-signed is installed. The bootloader directory in /boot/efi/EFI/ will be named &#039;debian&#039;.</p></div></blockquote></div><p>Does anyone know any virtualization option that supports Secure Boot in the guest, so one can try and understand what is going on in a successful Secure Boot?</p>]]></description>
			<author><![CDATA[dummy@example.com (Ulysses_)]]></author>
			<pubDate>Thu, 03 Dec 2020 20:12:51 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26077#p26077</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26076#p26076</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p>Ive not used antix or mx, i dont see the need for uefi boot or secure boot as mentioned by the limitations Head on a sticker mentions.</p></div></blockquote></div><p>It makes no sense that Microsoft would break what little security Secure Boot offers by allowing it to boot absolutely anything plugged into a usb port as long as it bothers to look live and EFI. Do you have any references for this unbelievable limitation?</p>]]></description>
			<author><![CDATA[dummy@example.com (Ulysses_)]]></author>
			<pubDate>Thu, 03 Dec 2020 20:01:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26076#p26076</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26075#p26075</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p>seems foxnews like or far right or&#160; even extremist fringe of the far right ideology.</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>I wonder how coked up the op is.</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>he doesn&#039;t know what he&#039;s talking about.</p></div></blockquote></div><p>These are political remarks and insults to a member who is not allowed by golinux to reply to political remarks and defend their reputation. You are punching an opponent with his hands tied. You have been reported.</p>]]></description>
			<author><![CDATA[dummy@example.com (Ulysses_)]]></author>
			<pubDate>Thu, 03 Dec 2020 20:00:37 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26075#p26075</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26069#p26069</link>
			<description><![CDATA[<div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>Ive just disabled uefi altogether</p></div></blockquote></div><p>No, you haven&#039;t. You&#039;ve enabled CSM (&quot;Legacy&quot; mode), which emulates non-UEFI booting via your machine&#039;s UEFI firmware. This means the machine is still open to the many UEFI firmware vulnerabilities.</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>my drives are encrypted so good luck to anyone who can get info off them</p></div></blockquote></div><p>If you have a rootkit then it can read the contents of the drive once the system is running. Secure Boot would help prevent rootkits from running. It&#039;s far from perfect but it is an extra layer of protection.</p><p>And before anybody starts bleating about not trusting Microsoft&#039;s keys note that it is possible to create your own keys, enrol them in the UEFI firmware and sign the kernel images with them. That&#039;s how I have enabled Secure Boot in my Alpine Linux system.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Thu, 03 Dec 2020 18:40:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26069#p26069</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26059#p26059</link>
			<description><![CDATA[<p>Ive not used antix or mx, i dont see the need for uefi boot or secure boot as mentioned by the limitations Head on a sticker mentions.</p><p>Ive just disabled uefi altogether, my drives are encrypted so good luck to anyone who can get info off them as i use serpent plus blowfish cipher keys. Ive also got a machine that is fully encrypted with openbsd using a separate bootloader on a usb. Much more secure than &quot;secure boot&quot; will ever be. Lock down the bios with a password and you have double the protection.</p>]]></description>
			<author><![CDATA[dummy@example.com (dice)]]></author>
			<pubDate>Thu, 03 Dec 2020 13:02:53 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26059#p26059</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26055#p26055</link>
			<description><![CDATA[<div class="quotebox"><cite>anticapitalista wrote:</cite><blockquote><div><div class="quotebox"><cite>Ulysses_ wrote:</cite><blockquote><div><p>Can&#039;t we mix some of MX into devuan?</p></div></blockquote></div><p>Why would you want to do that after this post of yours?</p><div class="quotebox"><blockquote><div><p>MX/AntiX is the work of a state-sponsored political extremist who is openly in the payroll of a state and at the same time pretends to be against the system. Can&#039;t be trusted for anything to do with security, privacy, cryptocurrencies, anti-surveillance. Might as well install ubuntu.</p></div></blockquote></div><p><a href="https://www.linuxquestions.org/questions/linux-security-4/how-to-discover-distros-that-are-signed-for-secure-boot-4175685259/#post6188829" rel="nofollow">https://www.linuxquestions.org/question … ost6188829</a></p><p>Read on for more laughs later in the same thread</p></div></blockquote></div><p>Wow, I read that and yeah, he doesn&#039;t know what he&#039;s talking about.</p><p>I wonder how coked up the op is. Sheesh...</p><p>That thread has a lot of red meat in it.&#160; Some of which seems foxnews like or far right or&#160; even extremist fringe of the far right ideology.&#160; If the op see&#039;s this message, just calm down. this is not helping anyone... people will only laugh at you for this lack of logic and paranoia...</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Thu, 03 Dec 2020 02:05:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26055#p26055</guid>
		</item>
		<item>
			<title><![CDATA[Re: How to make devuan boot with Secure Boot enabled the way antiX does it]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=26054#p26054</link>
			<description><![CDATA[<div class="quotebox"><cite>golinux wrote:</cite><blockquote><div><p>@Ulysses_ . . . no one here is interested in your political rants.&#160; If you want to continue posting here, please leave them at the door.</p></div></blockquote></div><p>I wouldn&#039;t say that, I find it amusing, but I do think it is a waste of oxygen that could otherwise be used to fuel our brains.</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Thu, 03 Dec 2020 02:00:02 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=26054#p26054</guid>
		</item>
	</channel>
</rss>
