Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Debian, Ubuntu, Red Hat, Fedora, Suse, Arch, Gentoo, and Slackware all support secureboot. After that I got tired of looking up linux distributions, so there are likely more.


Right but none of those verify /usr like Android, iOS, Windows, MacOS and ChromeOS do.


That's not part of secureboot's remit, but distros who do it are generally referred to as 'immutable distros'. Fedora Silverblue, CarbonOS, NixOS, GUIX, Endless OS, and Vanilla OS are a few.


None of the distros you list verifies the software installed by the package manager (except sometimes the kernel and the initrd) at boot time and refuses to finish the boot process if the verification fails. I guess an argument can be made that immutability would make it easier to achieve such a "verified boot process", but none of the distros you list has done the work.

Also, Silverblue's home page does not even list "secure" or "security" as one of the benefits of Silverblue. (They list reliable, atomic, the ability to revert the system, containerized, developer-friendly, no ads, "all your data belongs to you", and open-source.)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: