mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#CensorBoot

1 Beitrag1 Beteiligte*r0 Beiträge heute
Kevin Karhan :verified:<p>For those who didn't remember: <em>"<a href="https://infosec.space/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a>"</em> is a <a href="https://infosec.space/tags/scam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>scam</span></a> by <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> to shove their <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> infrastructure into systems and thus prevent <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> from rightfully taking over <a href="https://infosec.space/tags/Desktop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Desktop</span></a>|s: </p><ul><li>Why else did they <a href="https://www.youtube.com/watch?v=U7VwtOrwceo&amp;t=661s" rel="nofollow noopener" target="_blank">publicly admit that it's insecure</a> to the point that they didn't bother to use it on the <a href="https://infosec.space/tags/XboxOne" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XboxOne</span></a> and <a href="https://infosec.space/tags/XboxSeries" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XboxSeries</span></a> / <a href="https://infosec.space/tags/XboxSeriesS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XboxSeriesS</span></a> / <a href="https://infosec.space/tags/XboxSeriesX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XboxSeriesX</span></a> ? </li></ul><p><a href="https://en.wikipedia.org/wiki/UEFI#Secure_Boot_criticism" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/UEFI#Sec</span><span class="invisible">ure_Boot_criticism</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://t3n.social/@t3n" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>t3n</span></a></span> nicht wirklich ungewiss:</p><p><a href="https://infosec.space/tags/BestCase" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BestCase</span></a>: Leute lassen sich nicht von <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> verarschen, werweigern sivh <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> und schauen uaf <a href="https://endof10.org" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">endof10.org</span><span class="invisible"></span></a> nach Alternativen.</p><p>Wacheinlichstes Szenario: Tausende Tonnen 100% vermeidbarer <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> wird generiert aber die allermeisten System kommen billig in den Gebrauchtmarkt.</p><p><a href="https://infosec.space/tags/WorstCase" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WorstCase</span></a>: Tausende Tonnen 100% vermeidbarer <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> wird generiert!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://myside-yourside.net/@StarkRG" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>StarkRG</span></a></span> I agree and I do the same.</p><ul><li>It's just gotten so bad that I know companies are literally willing to pay <a href="https://infosec.space/tags/IdiotTax" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdiotTax</span></a> and trash perfectly fine hardware because <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> like <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> can't do <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> and/or <em>8 GB RAM are not enough</em> if you want to use more than 2 messengers at the time and still have like a ticketing system, wiki, softphone and eMail client open (aka. <a href="https://infosec.space/tags/TechSupport" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechSupport</span></a>)…</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@LaF0rge" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LaF0rge</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@sysmocom" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>sysmocom</span></a></span> granted, I do trust the GSMA more than Beijing, but that's more due to the fact that conflicting desires if GSMA members tend to be harder to steer.</p><ul><li>Similarly GAFAMs conflicting ideas prevented them from enshittifying Linux.</li></ul><p>Still, I think that end users and device integrators should have full control over the certificates and root of trust, including the ability to add alternative Root-CAs and even removing GSMA's Root-CA (similar to how <em>"Secure Boot"</em> should've been done instead of <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>!) </p><ul><li>Whether it would be a wise decision to yeet the GSMA cert is a different story, but given what I know in terms of <em>"security"</em> I'd certainly not trust <a href="https://infosec.space/tags/Bundesdruckerei" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bundesdruckerei</span></a> and it's subsidiaries to be competent.</li></ul><p>Certainly being able to exercise full control would make a lot of <a href="https://infosec.space/tags/osmocom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>osmocom</span></a>'s development easier.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://friendica.a-zwenkau.de/profile/franky" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>franky</span></a></span> <span class="h-card" translate="no"><a href="https://bonn.social/@ulrichkelber" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ulrichkelber</span></a></span> <span class="h-card" translate="no"><a href="https://sueden.social/@kontrollierterWahnwitz" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kontrollierterWahnwitz</span></a></span> es heißt <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>, denn <a href="https://infosec.space/tags/HoldenKeyBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HoldenKeyBoot</span></a> macht <em>"<a href="https://infosec.space/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a>"</em> unfixable unsicher!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@mrgrumpymonkey" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mrgrumpymonkey</span></a></span> it is.</p><p>One can repartition Windows installations on the fly whilst running (and even then there are tools like <a href="https://infosec.space/tags/Wubi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Wubi</span></a> that made it easy to setup <a href="https://infosec.space/tags/dualboot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dualboot</span></a> <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> &amp; <a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a>.</p><ul><li>ISOLINUX does allow for <em>"load image into RAM and boot"</em> setups. I literally use that on <span class="h-card" translate="no"><a href="https://infosec.space/@OS1337" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>OS1337</span></a></span> because no system that can boot it will have &gt; 16 MB RAM anyway ( 8 MB is the hard limit for bare linux kernel) so merely making Windows' bootloader to chainload <a href="https://infosec.space/tags/isolinux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>isolinux</span></a> to load that image in RAM and yeet it isn't out of the question.</li></ul><p>I just have neither a <a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> machine nor time and spoons to make such a tool, much less to basically create even said <em><a href="https://infosec.space/tags/ProofOfConcept" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProofOfConcept</span></a> "<a href="https://infosec.space/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a>"</em>…</p><ul><li>But thanks to <a href="https://infosec.space/tags/GoldenKeyBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GoldenKeyBoot</span></a>, <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> is unfixably insecure!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@mrgrumpymonkey" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mrgrumpymonkey</span></a></span> better even if you can build a <a href="https://infosec.space/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> that automagically installs <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> over a <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>'ed <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a>!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@Cheatha" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Cheatha</span></a></span> <em>nodds in agreement</em></p><p>Keep the envoirment safe, ditch <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> &amp; <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a>!</p><p><a href="https://enof10.org" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">enof10.org</span><span class="invisible"></span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@itsfoss" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>itsfoss</span></a></span> <em>nodds in agreement</em> the amount of <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> creates is s absurd, it'll make hee <a href="https://infosec.space/tags/EU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EU</span></a> converting to <a href="https://infosec.space/tags/IEC60906_1" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IEC60906_1</span></a> look like envoirmentally responsible by comparison. </p><ul><li>OFC <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>EUCommission</span></a></span> didn't do that citing 700.000t of <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> as argument against it.</li></ul><p>I wounder how many millions of PCs get replaced for no good reason because Microsofts's new <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> requires <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>! </p><p><a href="https://en.wikipedia.org/wiki/IEC_60906-1" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/IEC_6090</span><span class="invisible">6-1</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://blob.cat/users/Jain" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Jain</span></a></span> <span class="h-card" translate="no"><a href="https://brotka.st/users/kaia" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kaia</span></a></span> +9001%</p><p>Liegt eher an <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://eupolicy.social/@jmaris" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jmaris</span></a></span> <span class="h-card" translate="no"><a href="https://floss.social/@kde" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kde</span></a></span> I think getting rid of <a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> is the correct approach.</p><ul><li><a href="https://infosec.space/tags/EndOf10" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EndOf10</span></a> should also mark the end of <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> and a ban of <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> for creating thousands of tons of 100% avoidable <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> due to <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>.</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mk.moth.zone/@eri" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>eri</span></a></span> worse even is the <a href="https://infosec.space/tags/EoL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EoL</span></a> of <a href="https://infosec.space/tags/Winfows10" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Winfows10</span></a> and <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> mandating <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> for <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a>, thus generating.thousands of tons of 100% avoidable <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> in return!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://m.ai6yr.org/@ai6yr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ai6yr</span></a></span> and guess what: <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> caused this issue by mandating <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> via <a href="https://infosec.space/tags/TPM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TPM</span></a> 2.0 for no valid reason.</p><ul><li>This <em>is</em> an <a href="https://infosec.space/tags/EnvoirmentalCrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EnvoirmentalCrime</span></a> and they should be forced to undo the <em>harm caused</em>!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://digipres.club/@misty" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>misty</span></a></span> IMHO <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> &amp; <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> should be illegal for creating thousands of tons of 100% avoidable <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a>.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://union.place/@leguinian_utopia" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>leguinian_utopia</span></a></span> consider booting into an external SSD with <span class="h-card" translate="no"><a href="https://ubuntu.social/@ubuntu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ubuntu</span></a></span> preinstalled...</p><ul><li>That should work even on <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> machines...</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://qoto.org/@barefootstache" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>barefootstache</span></a></span> You could try <a href="https://infosec.space/tags/Ventoy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ventoy</span></a> which supports <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a>...</p><ul><li>That way you can just drag &amp; drop ISO files.</li></ul><p>Also consider enabling <a href="https://infosec.space/tags/CSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CSM</span></a> / <a href="https://infosec.space/tags/BIOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BIOS</span></a> mode if possible...</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mk.absturztau.be/@Eyedust" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Eyedust</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.space/@topher" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>topher</span></a></span> <em>exactly that</em> is my main gripe.</p><p>The reason the <a href="https://infosec.space/tags/EU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EU</span></a> refused to standardize upon <a href="https://en.wikipedia.org/wiki/IEC_60906-1#Possibility_of_acceptance_in_European_Union" rel="nofollow noopener" target="_blank">IEC 60906-1</a> was because they expected it to generate 700.000t of 100% avoidable <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> (or ~ 1,4 kg per EU citizen).</p><ul><li>IDK about you, but even if people were to only throw out mainboards due to <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> (which noone does!) we'd easily see way more eWaste due to <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> in the EU alone, yet <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>EUCommission</span></a></span> and <span class="h-card" translate="no"><a href="https://social.bund.de/@Bundesregierung" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Bundesregierung</span></a></span> don't even bat an eye.</li></ul><p>And that really infuriates me like this:</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.space/@topher" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>topher</span></a></span> the problem is the <a href="https://infosec.space/tags/Enshittifiaction" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enshittifiaction</span></a> and <a href="https://infosec.space/tags/Enfattening" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enfattening</span></a> of <a href="https://infosec.space/tags/Websites" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Websites</span></a> and <a href="https://infosec.space/tags/Applications" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Applications</span></a>! </p><p>Seriously, I think that <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> should be sued into insolvency for the way they create 100% avoidable <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> with <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> and <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> to the point that if I didn't have my current job, I'd basically collect all the old machines from companies that are stupid enough to use <a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> [and they'll likely give them away for free <em>minus SSDs / HDDs</em> instead of paying €5+ for <a href="https://infosec.space/tags/recycling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>recycling</span></a>], shove some <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> on [i.e. <a href="https://infosec.space/tags/RaspberryPiOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RaspberryPiOS</span></a>, <a href="https://infosec.space/tags/BunsenLabsLinux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BunsenLabsLinux</span></a> or <a href="https://infosec.space/tags/UbuntuLTS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UbuntuLTS</span></a>] and sell those off as <em>used electronics</em> for a good profit.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@ESETresearch" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ESETresearch</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@smolar_m" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>smolar_m</span></a></span> thanks for the post and research.</p><ul><li>Personally, I don't rely on <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> as I don't trust any <a href="https://infosec.space/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> that violates <a href="https://infosec.space/tags/KerckhoffsPrinciple" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KerckhoffsPrinciple</span></a>, but that's not my decision and being able to attest the security of it or at least have another way to <em>check for it</em> is kinda important.</li></ul><p>And yes I refuse to call it <em>"<a href="https://infosec.space/tags/SecureBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureBoot</span></a>"</em> because it is <em>not</em> secure by <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a>'s <a href="https://www.youtube.com/watch?v=U7VwtOrwceo&amp;t=739s" rel="nofollow noopener" target="_blank">own admission</a> - otherwise they would've relied on it on the <a href="https://infosec.space/tags/XboxOne" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XboxOne</span></a> and <a href="https://www.youtube.com/watch?v=U7VwtOrwceo&amp;t=233s" rel="nofollow noopener" target="_blank">not just the</a> <a href="https://infosec.space/tags/Xbox360" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Xbox360</span></a> !</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://burningboard.net/@Larvitz" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Larvitz</span></a></span> thanks for naming <em>yet another reason</em> why <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> is just <a href="https://infosec.space/tags/bad" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bad</span></a>. </p><ul><li>If the thousands of tons of 100% <a href="https://infosec.space/tags/Avoidable" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Avoidable</span></a> <a href="https://infosec.space/tags/eWaste" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eWaste</span></a> that <a href="https://infosec.space/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> created ain't enough... </li></ul><p>I wish <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>EUCommission</span></a></span> would work against shit like <a href="https://infosec.space/tags/CensorBoot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CensorBoot</span></a> as hard and effective as they did against <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>proprietary</span></a> <a href="https://infosec.space/tags/connectors" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>connectors</span></a> like <a href="https://infosec.space/tags/Apple" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Apple</span></a>'s <a href="https://infosec.space/tags/Lightning" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lightning</span></a>!</p>