I'm wondering why it makes sense to support unsigned bootloaders at all. Why not require a signature, always enroll a key rather than a hash, and complain bitterly when the key changes?
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Re: Hazards of user interaction
Date: 2012-10-12 11:13 pm (UTC)