|
|
|
|
|
by throwaway7767
3778 days ago
|
|
This seems to be an unfortunate relic from the fight against the clipper chip. Buying hardware that you don't own and control is a big problem, but that doesn't mean all methods of securing the boot process are evil. The important bit is that it's the owner of the hardware that's in control of the keys, and that (s)he can retain sole control of the signing keys if desired. |
|
https://libreboot.org/faq/#intel
The Snowden leak claimed that the NSA had special Intel chips, but no one has ever claimed Intel did a special production run. However, if they stole Intel's signing keys and internal documentation, they could just reflash the existing chips and Intel would not need to know a thing about it. Anyone who gets their hands on that information would be able to do the same and there is not a thing you can do about it beside using hardware where that is not possible.