Comment on What the Linux desktop really needs to challenge Windows

<- View Parent
vacuumflower@lemmy.sdf.org ⁨1⁩ ⁨day⁩ ago

MS has nothing to do with it, except that BitLocker is much better than anything any Linux distro has to offer today.

It’s a piece of software with closed source code. I am aware that people can hide (and have done so many times) a backdoor or a mistake in source code so that it’ll be harder to find than many problems in binaries without source provided.

Still harder to audit.

You need to have the disk decrypt without user input, and you can’t have the secret with the user. (As the user is untrusted - could be someone stealing the laptop.) The normal Linux user mantra of ”I own the machine” does not apply here. In this threat model, the corporation owns the machine, and in particular any information on it.

Smart cards?

Hate RHEL all you want, but first take a look at what distros have any kind of commercial support at all from software vendors. This is the complete list: RHEL, sometimes Rocky, sometimes Ubuntu.

I know.

Basically, corporate requirements go completely against the requirements of enthusiasts and power users. You don’t need Secure Boot to protect your machine from thieves, but a corporation needs Secure Boot to protect the machine from you.

Sigh. Okay.

source
Sort:hotnewtop