mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

8.1K
active users

#SecureBoot

9 posts9 participants0 posts today
openSUSE Linux<p><a href="https://fosstodon.org/tags/Secureboot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Secureboot</span></a>, seamless updates, and smarter system extensions: In this <a href="https://fosstodon.org/tags/oSC25" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oSC25</span></a> session, dive into major upcoming features like FDE+TPM in YaST2, <a href="https://fosstodon.org/tags/systemd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>systemd</span></a>-sysext on MicroOS, and new tools like <a href="https://fosstodon.org/tags/sndiff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sndiff</span></a>. A must-watch on future of openSUSE! <a href="https://youtu.be/MPMrlUj1sVA?si=bMjxsJtyIOEyqzgb" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">youtu.be/MPMrlUj1sVA?si=bMjxsJ</span><span class="invisible">tyIOEyqzgb</span></a></p>
Thorsten Leemhuis (acct. 4/4)<p>Habt ihr Texte mit Headlines wie "Vorbereiten auf Einschlag: <a href="https://social.tchncs.de/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> warnt vor Secure-Boot-Zertifikat-Update" und fürchtet jetzt, dass (a) eure jetzige <a href="https://social.tchncs.de/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a>-Distribution bald nicht mehr auf zukünftigen PCs bootet oder (b) zukünftigen Distris nicht auf euren jetzigen PCs?</p><p>Dazu besteht fürs Erste so gut wie kein Sorge, u.a., weil PC-BIOSe auch bei aktivem <a href="https://social.tchncs.de/tags/UEFI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UEFI</span></a> <a href="https://social.tchncs.de/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a> Code ausführen, der mit einem abgelaufenen Zertifikat signiert wurde (wie dem verbreiteten von MS, das bald abläuft). </p><p>Für Details, siehe dieser Post von <span class="h-card" translate="no"><a href="https://nondeterministic.computer/@mjg59" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mjg59</span></a></span>, der Shim entwickelt hat: <a href="https://mjg59.dreamwidth.org/72892.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">mjg59.dreamwidth.org/72892.html</span><span class="invisible"></span></a> </p><p>Viele Medien (darunter auch einige, die normalerweise super Qualität liefern) haben somit nur unnütz Panik verbreitet (und damit Geld verdient). <a href="https://social.tchncs.de/tags/Seufz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Seufz</span></a></p>
AskUbuntu<p>Ubuntu - Disable Secure Boot post-setup <a href="https://ubuntu.social/tags/dualboot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dualboot</span></a> <a href="https://ubuntu.social/tags/secureboot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>secureboot</span></a></p><p><a href="https://askubuntu.com/q/1553862/612" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">askubuntu.com/q/1553862/612</span><span class="invisible"></span></a></p>
heise online English<p>Security updates: UEFI security vulnerabilities jeopardize Lenovo All-in-One PCs</p><p>Various Lenovo All-in-One PC models are vulnerable. The description of the vulnerabilities suggests that Secure Boot can be bypassed. </p><p><a href="https://www.heise.de/en/news/Security-updates-UEFI-security-vulnerabilities-jeopardize-Lenovo-All-in-One-PCs-10505438.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/en/news/Security-upda</span><span class="invisible">tes-UEFI-security-vulnerabilities-jeopardize-Lenovo-All-in-One-PCs-10505438.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/Lenovo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lenovo</span></a> <a href="https://social.heise.de/tags/Patchday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Patchday</span></a> <a href="https://social.heise.de/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a> <a href="https://social.heise.de/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://social.heise.de/tags/Sicherheitsl%C3%BCcken" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sicherheitslücken</span></a> <a href="https://social.heise.de/tags/UEFI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UEFI</span></a> <a href="https://social.heise.de/tags/Updates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Updates</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>news</span></a></p>
heise Security<p>Sicherheitsupdates: UEFI-Sicherheitslücken gefährden All-in-One-PCs von Lenovo</p><p>Verschiedene All-in-One-PC-Modelle von Lenovo sind verwundbar. Die Beschreibung der Lücken legt ein Aushebeln von Secure Boot nahe. </p><p><a href="https://www.heise.de/news/Sicherheitsupdates-UEFI-Sicherheitsluecken-gefaehrden-All-in-One-PCs-von-Lenovo-10505157.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Sicherheitsupdat</span><span class="invisible">es-UEFI-Sicherheitsluecken-gefaehrden-All-in-One-PCs-von-Lenovo-10505157.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/Lenovo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lenovo</span></a> <a href="https://social.heise.de/tags/Patchday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Patchday</span></a> <a href="https://social.heise.de/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a> <a href="https://social.heise.de/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://social.heise.de/tags/Sicherheitsl%C3%BCcken" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sicherheitslücken</span></a> <a href="https://social.heise.de/tags/UEFI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UEFI</span></a> <a href="https://social.heise.de/tags/Updates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Updates</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>news</span></a></p>
The New Oil<p>New <a href="https://mastodon.thenewoil.org/tags/Lenovo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lenovo</span></a> <a href="https://mastodon.thenewoil.org/tags/UEFI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UEFI</span></a> <a href="https://mastodon.thenewoil.org/tags/firmware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>firmware</span></a> updates fix <a href="https://mastodon.thenewoil.org/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a> bypass flaws</p><p><a href="https://www.bleepingcomputer.com/news/security/new-lenovo-uefi-firmware-updates-fix-secure-boot-bypass-flaws/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/new-lenovo-uefi-firmware-updates-fix-secure-boot-bypass-flaws/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a></p>
nemo™ 🇺🇦<p>🚨 Lenovo releases urgent UEFI firmware updates to fix 6 high-severity Secure Boot bypass vulnerabilities affecting IdeaCentre &amp; Yoga AIO desktops! Update now to protect against stealthy firmware attacks. 🔐⚙️ <a href="https://mas.to/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mas.to/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a> <a href="https://mas.to/tags/FirmwareUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FirmwareUpdate</span></a> <a href="https://mas.to/tags/Lenovo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lenovo</span></a> <a href="https://mas.to/tags/newz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>newz</span></a> </p><p>Details &amp; updates 👉 <a href="https://www.bleepingcomputer.com/news/security/new-lenovo-uefi-firmware-updates-fix-secure-boot-bypass-flaws/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/new-lenovo-uefi-firmware-updates-fix-secure-boot-bypass-flaws/</span></a></p>

AllinOne-Geräte von Lenovo IdeaCentre AIO 3 24ARR9, 27ARR9, sowie Yoga AIO 27IAH10, 32ILL10, und 32IRH8 brauchen ein Firmwareupdate. Für das IdeaCenter AIO 3 gibt es das schon. Updaten!
Für die betroffene Yoga-Baureihe erst ab September.
support.lenovo.com/us/en/produ
Hintergrund: Lenovo warnt vor schwerwiegenden Fehlern, die es Angreifern ermöglichen könnten, Secure Boot auf All-in-One-Desktops mit angepasster Insyde UEFI-Firmware zu umgehen.
insyde.com/security-pledge/sa-

#SecureBoot
#Gentoo

So I am trying to ensure the setups on my laptops are secureboot setup this time. I figure its a decent idea to keep with some kind of standard there.

I rebuilt the HP because my full disk encryption setup was just too irritating. Gonna have to just keep encryption to external drives I suppose.

Microsoft has a signing key that many #Linux distributions use to support #SecureBoot, and that key expire on September 11, 2025

A replacement key has existed since 2023, but apparently - many systems don’t support it yet

Fixing this problem requires firmware updates from original equipment manufacturers (OEM) but there is a risk that not all OEMs will issue updates - especially those for older, or less popular devices
techradar.com/pro/security/lin

TechRadar · Linux users are about to face another major Microsoft Secure Boot issueBy Sead Fadilpašić

Some Linux users might be interested, reading about this (Subscriber link, that bypasses the Paywall, since I find this information important to spread for awareness):

lwn.net/SubscriberLink/1029767

„Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft that is set to expire in September. After that point, Microsoft will no longer use that key to sign the shim first-stage UEFI bootloader that is used by Linux distributions to boot the kernel with Secure Boot. But the replacement key, which has been available since 2023, may not be installed on many systems; worse yet, it may require the hardware vendor to issue an update for the system firmware, which may or may not happen.“

LWN.netLinux and Secure Boot certificate expirationLinux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a ke [...]