Linux 6.9 Makes a Change to Satisfy Microsoft for EFI x86 Shim Loader Signing
phoronix.com
phoronix.com
[0] https://lore.kernel.org/linux-efi/20240308085754.476197-7-ar...
[1] https://lore.kernel.org/linux-efi/20240308085754.476197-8-ar...
[2] https://lore.kernel.org/linux-efi/20240308085754.476197-9-ar...
[3] https://lore.kernel.org/linux-efi/20240308085754.476197-10-a...
[4] https://lore.kernel.org/linux-efi/20240308085754.476197-11-a...
[5] https://lore.kernel.org/linux-efi/20240308085754.476197-12-a...
[6] https://lore.kernel.org/linux-efi/CAMj1kXEoLOshENQO=RjQRq48D...
If it were crystal clear what the need being satisfied were, these patches would probably explain themselves.
https://techcommunity.microsoft.com/t5/hardware-dev-center/n...
If you start needing to buy specialist hardware before you can even try out something other than Windows, the barrier to entry and inertia this creates will mean less and less people ever even develop a desire to try it.
tangential example: banking apps on non-google androids
Open source doesn't necessarily imply it is secure. Security isn't free and open source projects can struggle funding such development.
>byte-reproducible builds
This is mostly a party trick. Meanwhile the system is one curl | sh away from having all its cookies stolen, files cryptolocked, mic spied on, keylogger installed, clipboard sniffed, etc. Reproducible builds can't save you from insecure design which my comment was referring to investing in fixing and is what this patch being highlighted in the article is doing.
>it's also the premier malware target
Having a large market share is why. If Linux overnight gained a ton of marketshare the malware situation would be worse than windows.