Hacker News new | ask | show | jobs
by p_l 3731 days ago
Except that "Setup Mode" exists and every serious computing device that uses Secure Boot provides it, because big business customers wants it.

What is "Setup Mode"? It's "load your own root of trust and wipe any preinstalled keys". Nothing, nothing says that the root of trust has to be from Microsoft or Intel (and Secure Boot specification that is tested for Windows Logo certification would reject such system unless manufactured by Microsoft or Intel).

The difference with jumper is that you have standardized APIs etc. for the signing process, including a standardized "jumper".