← Back to context

Comment by Strom

12 hours ago

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Afaict, you can't disable driver signature enforcement permanently without disabling secure boot.

  • Secure boot is an anti-feature in most of the landscape anyway. Sure, if you have a distribution under your control or influence it could theoretically be a benefit. But you need to not be stupid or naive here.

    You can also roll you own encryption if you are not stupid and naive. Probably a question of self-reflection.