5/13/2026 at 11:29:11 AM
Secure boot protects against evil maid attacks, but no one would ever need use an evil maid attack on a NixOS user because anyone can merge whatever they want to NixOS without signature or review, particularly given that any maintainer can merge their own commits from their own pseudonyms.NixOS is always one compromised Github API token away from a backdoor into everything built with NixOS.
I cannot imagine a threat model that would need secure boot yet accept the risks of NixOS.
by lrvick