boot guard would be even better if advanced users had an option of having their signing key flashed into the chip. Then you can have best of both worlds. Coreboot team can sign the firmware and owner can verify and re-sign. Or build on their own and sign.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Re: boot guard would be even better if
Date: 2015-02-17 03:25 am (UTC)And please no NDAs.