• installation-guide: secure boot vs. boothole

    From Holger Wansing@21:1/5 to All on Sun Dec 26 15:00:02 2021
    Hi all,

    on the german l10n mailinglist a topic came up regarding the 'secure boot' chapter in the installation-guide: https://d-i.debian.org/manual/en.amd64/ch03s06.html#secure-boot


    It was stated, that the manual declares Secure Boot as an unproblematic function. And this in an unauthorized way, when looking at the BootHole security issues.


    What do you think?
    Should we mention these security issues (or the basic background behind all this) in the guide? We may add a link to https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot/
    as an overview page for this topic.

    Or do we ignore this - saying, that all software could have it's hidden security holes and therefore there is no need to point out this explicitly
    for the Secure Boot function?


    Holger



    --
    Holger Wansing <hwansing@mailbox.org>
    PGP-Fingerprint: 496A C6E8 1442 4B34 8508 3529 59F1 87CA 156E B076

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Steve McIntyre@21:1/5 to Holger Wansing on Mon Jan 3 15:40:02 2022
    Hi Holger! Happy New Year!

    On Sun, Dec 26, 2021 at 02:50:32PM +0100, Holger Wansing wrote:

    on the german l10n mailinglist a topic came up regarding the 'secure boot' >chapter in the installation-guide: >https://d-i.debian.org/manual/en.amd64/ch03s06.html#secure-boot


    It was stated, that the manual declares Secure Boot as an unproblematic >function. And this in an unauthorized way, when looking at the BootHole >security issues.


    What do you think?
    Should we mention these security issues (or the basic background behind all >this) in the guide? We may add a link to >https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot/
    as an overview page for this topic.

    Or do we ignore this - saying, that all software could have it's hidden >security holes and therefore there is no need to point out this explicitly >for the Secure Boot function?

    I personally don't think it's worth highlighting here specifically, no.

    --
    Steve McIntyre, Cambridge, UK. steve@einval.com Can't keep my eyes from the circling sky,
    Tongue-tied & twisted, Just an earth-bound misfit, I...

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)