rene_mobile’s avatarrene_mobile’s Twitter Archive—№ 6,416

        1. …in reply to @taviso
      1. …in reply to @rene_mobile
        @taviso @halvarflake @julianor @coolhandle01 @fugueish @alexstamos @sleevi_ @durumcrustulum @LeaKissner It's not that *I* couldn't rebuild the Debian source, add my own Secure Boot signing key to my UEFI config, etc. It's that I don't have the time or patience to do it for or walk all other users through the process (and honestly, very rarely do it myself anymore).
    1. …in reply to @rene_mobile
      @taviso @halvarflake @julianor @coolhandle01 @fugueish @alexstamos @sleevi_ @durumcrustulum @LeaKissner And yes, I assume that parts of the Debian build and package distribution infrastructure can be compromised: debian.org/News/2003/20031202
  1. …in reply to @rene_mobile
    @taviso @halvarflake @julianor @coolhandle01 @fugueish @alexstamos @sleevi_ @durumcrustulum @LeaKissner I know that you know how Secure Boot works. I was trying to argue why I think in the specific example of Debian, it answers your questions: a) it's as open source as it gets b) the build infra can be compromised c) I wouldn't recommend most users to install without the Debian sig