BIOS vs EFI vs coreboot vs libreboot

Secure Boot with Microsoft key isn’t worthwhile. References:

Less worthwhile with leaked Microsoft secure boot key.

Secure Boot brings shim into the mix, which is also not great… →

Without full Verified Boot, without Sovereign Boot, it’s not worthwhile.

TPM for? Verified boot / Measured Boot? Not needed until implemented.

There are no microcode updates for VMs.

Note: This forum thread is in the Whonix forums. So the only place where Whonix - as long as runs “primarily” inside VMs (ignoring physical isolation) - could flip the BIOS vs EFI setting is on the virtualizer settings level. And for that - at the time of writing - no sufficient rationale exists.

Whonix doesn’t run on hardware yet until Whonix-Host Operating System Live ISO, Whonix-Host Installer is available.

Even if Whonix-Host existed, the decision of BIOS or EFI depends on the host hardware. It’s not something that can be adjusted from within Whonix source code level. Modern hardware comes with EFI by default anyhow and does not even have BIOS compatibility module. So your EFI-only feature request on modern hardware is automatically fullfilled without any changes by Whonix required.

2 Likes