As I understand it, it’s Microsofts attempt to only allow booting kernels signed by them or their partners. In theory this stops malicious attacks from changing the kernel and have it booted. But Secure Boot is just something you can turn off.
Not only that, earlier this year, it was discovered that there was a flaw in Secure Boot that meant it never even did the one thing it was supposed to do. This update is designed to make it functional for the first time.
As I understand it, it’s Microsofts attempt to only allow booting kernels signed by them or their partners. In theory this stops malicious attacks from changing the kernel and have it booted. But Secure Boot is just something you can turn off.
Not only that, earlier this year, it was discovered that there was a flaw in Secure Boot that meant it never even did the one thing it was supposed to do. This update is designed to make it functional for the first time.