this post was submitted on 30 Oct 2023
611 points (93.1% liked)
Technology
60113 readers
2048 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Your statements made me believe the opposite. Though I wasn't condescending. I said it was OK to not know.
Microsoft doesn't say that. They state it adds to the security of your computer before Windows even starts. https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/secure-the-windows-10-boot-process
Any device security is multi layered.
Having a mechanism that only accepts trusted boot binaries is pretty critical to fighting malware. Rootkits effectively have total control of whatever you decide to boot because of their persistence. When your hardware has its own security features (Secure Boot, TPM) why not take advantage of them to make the software you run more secure?
If you didn't know, Android, macOS and iOS have their own TPM and Secure Boot implementations that have been enforced and present for over a decade.
And those secureboot implementations in mobile devices are frequently called out as primarily a way to prevent usage that the manufacturer doesn’t want you to do.