Hacker News new | ask | show | jobs
by Klathmon 2882 days ago
Yes, but it's not either-or, both can be used.

Combined with a TPU that wipes keys when secure boot is enabled/disabled gives a pretty secure system, that still allows you to "eject" to an unsigned boot when needed.