@iska @safiuddinkhan @cyberspook @m0xee @dushman Verified boot does not exist in normal PCs. Verified boot is not the same as secure boot, it is an extra layer above which protects the OS integrity, not just checking the bootloader signature. You are very wrong.
Follow

@inference @safiuddinkhan@fosstodon.org @cyberspook @iska@mstdn.starnix.network @dushman What's with the TPM 2.0 requirement of Windows then? Is it to verify bootloader only? I don't think so.
They've made it mandatory in Windows 11 only, but it was there way earlier than that.

@m0xee @safiuddinkhan @cyberspook @iska @dushman Yes, it's for secure boot. Windows root filesystem is modifiable, so it cannot have integrity checking.

Verified boot locks the root FS as read-only, so malware and corruption cannot persist. It is restored to its previous state on reboot.
Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml