Indeed.
As soon as lanzaboote works with stable, I'll go back to stable (but I think that is not the case yet, sadly).
Lowkey plug for lanzaboote though. Getting secure boot working went pretty well for me thanks to it.
As soon as lanzaboote works with stable, I'll go back to stable (but I think that is not the case yet, sadly).
Lowkey plug for lanzaboote though. Getting secure boot working went pretty well for me thanks to it.
I suppose in combination with LUKS you could at least prevent evil maid attacks, to the extent that your machine's firmware is actually secure, but it seems like a lot of work for just that...
I didn't have some strong security-driven mindset behind it.
That said I did also lock down my BIOS with a password (to prevent disabling secure boot).
I'm keen for secure boot and TPM FDE, and would like to see lanzaboote in nixpkgs.