http://mjg59.dreamwidth.org/5552.html?thread=102832#cmt102832 and http://mjg59.dreamwidth.org/5850.html seem to state Matthew's solution - ship systems with no keys installed.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Matthew described a solution in a previous post
Date: 2011-10-02 11:41 am (UTC)