frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Portable C Compiler

https://en.wikipedia.org/wiki/Portable_C_Compiler
1•guerrilla•2m ago•0 comments

Show HN: Kokki – A "Dual-Core" System Prompt to Reduce LLM Hallucinations

1•Ginsabo•2m ago•0 comments

Software Engineering Transformation 2026

https://mfranc.com/blog/ai-2026/
1•michal-franc•3m ago•0 comments

Microsoft purges Win11 printer drivers, devices on borrowed time

https://www.tomshardware.com/peripherals/printers/microsoft-stops-distrubitng-legacy-v3-and-v4-pr...
2•rolph•4m ago•0 comments

Lunch with the FT: Tarek Mansour

https://www.ft.com/content/a4cebf4c-c26c-48bb-82c8-5701d8256282
1•hhs•7m ago•0 comments

Old Mexico and her lost provinces (1883)

https://www.gutenberg.org/cache/epub/77881/pg77881-images.html
1•petethomas•10m ago•0 comments

'AI' is a dick move, redux

https://www.baldurbjarnason.com/notes/2026/note-on-debating-llm-fans/
2•cratermoon•12m ago•0 comments

The source code was the moat. But not anymore

https://philipotoole.com/the-source-code-was-the-moat-no-longer/
1•otoolep•12m ago•0 comments

Does anyone else feel like their inbox has become their job?

1•cfata•12m ago•0 comments

An AI model that can read and diagnose a brain MRI in seconds

https://www.michiganmedicine.org/health-lab/ai-model-can-read-and-diagnose-brain-mri-seconds
1•hhs•15m ago•0 comments

Dev with 5 of experience switched to Rails, what should I be careful about?

1•vampiregrey•17m ago•0 comments

AlphaFace: High Fidelity and Real-Time Face Swapper Robust to Facial Pose

https://arxiv.org/abs/2601.16429
1•PaulHoule•18m ago•0 comments

Scientists discover “levitating” time crystals that you can hold in your hand

https://www.nyu.edu/about/news-publications/news/2026/february/scientists-discover--levitating--t...
1•hhs•20m ago•0 comments

Rammstein – Deutschland (C64 Cover, Real SID, 8-bit – 2019) [video]

https://www.youtube.com/watch?v=3VReIuv1GFo
1•erickhill•21m ago•0 comments

Tell HN: Yet Another Round of Zendesk Spam

1•Philpax•21m ago•0 comments

Postgres Message Queue (PGMQ)

https://github.com/pgmq/pgmq
1•Lwrless•25m ago•0 comments

Show HN: Django-rclone: Database and media backups for Django, powered by rclone

https://github.com/kjnez/django-rclone
1•cui•27m ago•1 comments

NY lawmakers proposed statewide data center moratorium

https://www.niagara-gazette.com/news/local_news/ny-lawmakers-proposed-statewide-data-center-morat...
1•geox•29m ago•0 comments

OpenClaw AI chatbots are running amok – these scientists are listening in

https://www.nature.com/articles/d41586-026-00370-w
2•EA-3167•29m ago•0 comments

Show HN: AI agent forgets user preferences every session. This fixes it

https://www.pref0.com/
6•fliellerjulian•31m ago•0 comments

Introduce the Vouch/Denouncement Contribution Model

https://github.com/ghostty-org/ghostty/pull/10559
2•DustinEchoes•33m ago•0 comments

Show HN: SSHcode – Always-On Claude Code/OpenCode over Tailscale and Hetzner

https://github.com/sultanvaliyev/sshcode
1•sultanvaliyev•34m ago•0 comments

Microsoft appointed a quality czar. He has no direct reports and no budget

https://jpcaparas.medium.com/microsoft-appointed-a-quality-czar-he-has-no-direct-reports-and-no-b...
2•RickJWagner•35m ago•0 comments

Multi-agent coordination on Claude Code: 8 production pain points and patterns

https://gist.github.com/sigalovskinick/6cc1cef061f76b7edd198e0ebc863397
1•nikolasi•36m ago•0 comments

Washington Post CEO Will Lewis Steps Down After Stormy Tenure

https://www.nytimes.com/2026/02/07/technology/washington-post-will-lewis.html
13•jbegley•36m ago•3 comments

DevXT – Building the Future with AI That Acts

https://devxt.com
2•superpecmuscles•37m ago•4 comments

A Minimal OpenClaw Built with the OpenCode SDK

https://github.com/CefBoud/MonClaw
1•cefboud•38m ago•0 comments

The silent death of Good Code

https://amit.prasad.me/blog/rip-good-code
3•amitprasad•38m ago•0 comments

The Internal Negotiation You Have When Your Heart Rate Gets Uncomfortable

https://www.vo2maxpro.com/blog/internal-negotiation-heart-rate
1•GoodluckH•39m ago•0 comments

Show HN: Glance – Fast CSV inspection for the terminal (SIMD-accelerated)

https://github.com/AveryClapp/glance
2•AveryClapp•40m ago•0 comments
Open in hackernews

Managing EFI boot loaders for Linux: Controlling secure boot (2015)

https://www.rodsbooks.com/efi-bootloaders/controlling-sb.html
57•CaliforniaKarl•6mo ago

Comments

sylware•6mo ago
"You better have those software rid of security flaws properly signed!"

...

phoronixrly•6mo ago
The guide is great and I've followed it to success several times. It fails whenever the odd vendor decides it should really offer a slightly buggy implementation.

For example one that will allow you to enter sb setup mode, clear EFI keys, but not offer a way to enroll new ones from the firmware setup UI. While simultaneously making the EFI KeyTool fail enrollment with a cryptic error message. :)

jeroenhd•6mo ago
While the commands and procedures on this page still work fine (the screenshots are a welcome addition!), I find the Arch Linux wiki to be a bit more up to date: https://wiki.archlinux.org/title/Unified_Extensible_Firmware...

The Arch wiki also adds some additional warnings that you may want to check into. For instance, my Thinkpad with an Nvidia GPU will be bricked if I use the normal API to load secure boot keys, because on boot certain firmware is executed before the setup utility, which means that if that firmware fails verification, the entire laptop becomes unbootable. The workaround (load keys through the UEFI setup utility instead of any other tools) doesn't let me get rid of the manufacturer keys and take full control, unfortunately. I'll keep Lenovo's choices here in mind next time I buy a laptop.

Thanks to updates to sbctl, you can create keys with `sbctl create-keys` rather than typing out complex openssl commands. sbctl's `enroll-keys` should also make the key enrollment procedure easier.

Your distro probably also comes with an optional package manager hook so you don't need to repeat the sign commands every time your bootloader updates.

Foxboron•6mo ago
>Thanks to updates to sbctl, you can create keys with `sbctl create-keys` rather than typing out complex openssl commands. sbctl's `enroll-keys` should also make the key enrollment procedure easier.

I mean, reading Rod Smiths post is what originally made me write secure boot tooling many years ago. I didn't understand why it had to be soooo complicated.

If you read the original `efi-roller` project I started out with you'll see it's largely just a wrapper around the stuff in Rod Smiths book, that was later refined by actually implementing a proper library in Go and tooling on top.

https://github.com/Foxboron/efi-roller

jeroenhd•6mo ago
It was definitely the most comprehensive article on actually using secure boot at the time it was written, that's for sure.

I just don't want people to think that now, a decade later, you still need to mess with shell scripts calling openssl commands to get secure boot to work.

tiberious726•6mo ago
If you use the -m flag with enroll-keys, won't that also load the MS keys, which the Nvidia firmware should be signed by, allowing verification to pass?
jeroenhd•6mo ago
Probably. There's also a Lenovo key in there, I believe, which sbctl probably doesn't know about.

My laptop is out of warranty and I'm not interested in starting a legal battle should the firmware bug persist and soft brick the motherboard, so I'm not going to try it.

edoceo•6mo ago
Does anyone use UEFI to directly load Linux ? Currently I use Syslinux but I've heard it can be directly booted and remove Syslinux from the process. And it still works with initrd and my appended command line options. This page is in my pinned reference for it - but I'm nervous to try lest I brick my machine.

Anyone here made it work? If UEFI can do it, what is the bootloader for?

Foxboron•6mo ago
The Linux `vmlinuz` binary is an EFI executable that implements a minimal stub loader to load rest of the kernel and initrd.

You can use `efibootmgr` to insert the `vmlinuz` binary as a boot entry. But honestly, you are better off using a proper bootloader as it makes things a lot simpler for you to manage.

The UEFI bootloader menu is mediocre if you are lucky, terrible in most cases.

Cu3PO42•6mo ago
Yes, you can boot Unified Kernel Images (UKI) directly from UEFI without an additional bootloader. A bootloader may still be helpful to manage your various entries and provide you with a menu to select one of many entries to boot.
mixmastamyk•6mo ago
Yes, I tried this on a tablet and it works. However I found systemd-boot friendlier to use at boot time, because you don’t have to go into firmware to pick an entry (kernel). And can edit config on disk.

But on a typical boot it works just fine either way.

jeroenhd•6mo ago
As others said, you can do it. It's very useful for some scenarios.

Bootloaders and boot managers take away a lot of the management, which is welcome with many UEFI screens. You have some, like HP's, that will let you browse to an EFI file and/or manually manage custom entries, basically removing the need for a bootloader in most cases, and then there are the ones like my MSI board that will corrupt their own configuration if you call efibootmgr too many times and that hide any custom boot defintions from the management UI so you have to use the Linux command line to set the preference right.

Whether you need one is up to you to decide. Most distros default to using a bootloader because that's what users expect, but there's no strict requirement for using bootloaders if you don't want Grub or rEFInd or systemd-boot on your system. However, if you want to do things like "edit the kernel parameters once every now and then", a bootloader is probably the way to go for most people.

When you're building an embedded Linux application that will only boot kernels signed by your company, I don't see the need for a bootloader, though.