Comment by msla

8 hours ago

With Windows, you get what you pay for.

In this case, that's an OS controlled by an unaccountable company that can take application software away from you.

Related: If you're the customer, you're the product.

you can always either disable secureboot and driver signature verification, or (the better solution) just enroll your own certificate in your TPM and sign the driver with that...

  • Ah, yes, the [insert super inconvenient and complex thing to do that most people don’t know, want or should do] will solve it! And when that fails, surely the user can just write their own OS, right? Bunch of skill-issued complainers we the users are.

    • Well, the hope was always that those of us inconvenienced by M$ would all collectively contribute to making Linux distros more convenient for everyone. But we can't ever seem to get inconvenienced enough to actually sufficiently mobilize and/or coordinate such an effort.

      2 replies →

    • I mean, the super-easy option would be to just use BitLocker for FDE. No hassles, just works. But I fugured since everyone here on HN hates MS I wouldn't even bring that up. Don't trust MS? Enroll yourown keys

      1 reply →

  • > or (the better solution) just enroll your own certificate in your TPM and sign the driver with that...

    I'll tell Grandma that's what she needs to do.