That's not a fair assessment. Linux used a whitelisted shim, which only included accepted entries in an easy-to-edit/hack EFI variable. Imagine writing your secret password on a normal VFAT partition that any OS can boot/read/change. This is the equivalent.
The proper way is to enroll the private keys with the bios, and sign the payloads yourself (or let your distribution handle that), which is way more secure and can be automatized if you select the custom secureboot.
Happy to be corrected if things have changed since the last time I looked at things.
But a method of doing that wasn't included in the UEFI standard for obvious Microsoft reasons, so few vendors support it and those that do usually don't do it correctly, let alone in a standardised way.
Not always possible. Depends on firmware support and we all know how shitty proprietary firmware can be.
When you control the keys, SecureBoot is a good thing at least as good as encryption!
There are things that are fair to complain about, but on this, I don't see how Microsoft or anyone could have done any better to be playing nice with Linux while helping customers.
I have computers that don't have this feature.
> When you control the keys, SecureBoot is a good thing at least as good as encryption!
I agree. It's all about who owns the keys to the machine. If we do, then it's all good.
2022 - Year of the Linux Desktop?
last week i installed the same OS on an old machine for a relative, on a "fresh SSD" so no dual boot nonsense and it had problems right out of the box. Like memory leaks and printers wont install because apparently sane-devel cannot be found by HP install utility. Long story short, the printer is still not installed on that machine, it works but i had to install some alternate software like system monitors instead of supplied ones. Dunno, maybe that one was a dud but i definitely feel the pain points as are being described across the spectrum. the problem is, if i cannot set up the machine in say half an hour without any tinkering, that is a win and i expect someone else to follow the on-screen commands but we do have a lot to cover and that is not in a bad way. i am a full time linux user so i am a part of this community but its not prime-time ready yet. I have installed windows 7 thousands of times, it always works. unless there is a hardware issue, out of the box the system works. that is not true on our side.
i have to say it but the last years linus-linux challenge needs to be appreciated and we need to do more tests like these and keep fixing those small and big issues.