Post B4xMVnR4s09fDnn11M by jessew@mk.cpluspatch.com
 (DIR) More posts by jessew@mk.cpluspatch.com
 (DIR) Post #B4xLzR6qLM2Ui8tWym by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       i have finally vanquished the beast (UKIs with secure boot on Arch)
       
 (DIR) Post #B4xM77NzYgaTrAZwnI by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       you gotta chain dracut and kernel-install and systemd-ukify and sbctl but when i figured it out it worked great
       
 (DIR) Post #B4xM7tXYWQl5CjQGMi by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com what's UKI
       
 (DIR) Post #B4xMLUjPYc8aJcS8Nk by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be unified kernel image, basically the modern way to package the initramfs and associated gizmos on UEFI systems (that is to say all systems)
       
 (DIR) Post #B4xMLUuOtkvarhauVk by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com that is to say NOT my cool 15 year old laptop ​:neofox_floof_explode:​
       
 (DIR) Post #B4xMQIohHdQqoJDYzg by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be it's way better than the old system but most distros haven't adopted it yet
       
 (DIR) Post #B4xMQJ1oUrvLSzM2RE by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be oh yeah also with UKIs you can remove the bootloader altogether and directly boot the kernel itself through the firmware boot sélection screen
       
 (DIR) Post #B4xMQJDrm3Z64MzfE0 by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com oh yeah that, yeah i did that on my debian if i recall right because i fucked my grub that one time and since i boot from here
       
 (DIR) Post #B4xMVXl39yckb70jvk by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be whoops
       
 (DIR) Post #B4xMVXwOTnhLAIJnc0 by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com no bios updates since 2010 and it has cpu vulnerabilities but its so cute i wish libreboot would go on it, or some kind of libre EFI i want EFI on it
       
 (DIR) Post #B4xMVnR4s09fDnn11M by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be you can also do a bunch of additional cool stuff with it like LUKS TPM unlocking and better Secure Boot support and whatnot
       
 (DIR) Post #B4xMXPMbLBzb8sSqvY by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com i always gets some weird log about TPM chip or some shit. idk what it does
       
 (DIR) Post #B4xMfWrrKAryjTxPyy by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be the Trusted Platform Module is a cryptography/security thingbasically to simplify it, it's a chip on your motherboard designed in such a way that it's impossible to tamper with and can contain sensitive data with no risk of someone desoldering it and stealing the data or something
       
 (DIR) Post #B4xMhZgZomJ23GehWq by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com what do you put in there? your weed? i can put my password in it?
       
 (DIR) Post #B4xMmD2pQNdTHOH1Ye by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be it's tied to your motherboard
       
 (DIR) Post #B4xMoEYMmo8UXOzTZQ by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be i put my main disk decryption key so i don't ever have to type the password on boot and it just auto unlocks
       
 (DIR) Post #B4xMoyHGmhnCLhLTJA by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com damn, goes hard
       
 (DIR) Post #B4xMuFJ0tyU8bnfyvQ by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be yeah and if someone just removes the SSD and puts it on another motherhboard it'll just ask for the password again
       
 (DIR) Post #B4xMuwj3T1rjH1BszA by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com i wanna do that
       
 (DIR) Post #B4xN1Zb7r2jRZRdrBg by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be a ton of programs use the TPM nowadays especially for payment stuff and video game anticheat
       
 (DIR) Post #B4xN1vY2FDKdeEMhQO by Stellar@mk.absturztau.be
       0 likes, 0 repeats
       
       @jessew@mk.cpluspatch.com gross
       
 (DIR) Post #B4xNK7T4fHbLpUifIW by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be no it's good, it skips the need for much more invasive security measures that can be spoofed anywaythe TPM is guaranteed unspoofable which makes life much easier
       
 (DIR) Post #B4xNQctEkez71L3kWm by jessew@mk.cpluspatch.com
       0 likes, 0 repeats
       
       @Stellar@mk.absturztau.be like instead of fingerprinting you, a video game can simply ban a cheater's hardware ID (unspoofable if you use tpm and secure boot) to force them to buy a new motherboard if they want to make new alts
       
 (DIR) Post #B4xOU8LgLRiHPYbJAm by mateusz6768@esp32fedi.cjdgrevival.com
       0 likes, 0 repeats
       
       CC: @jessew@mk.cpluspatch.comme too for my old laptop that has a Celeron N2840 that hasn't received BIOS updates in nearly a decade, coreboot would be fun for it