Hacker News new | ask | show | jobs
by londons_explore 2661 days ago
Perhaps it's time to move towards the Android/iOS model of having the OS unencrypted (since that isn't a secret anyway), and only do encryption of all the user data and apps.

That way, the OS can get to the login prompt entirely without secret data.

Obviously that's a big architecture change...

2 comments

At a bare minimum you still need to sign the OS in order to prevent tampering.
How would one guarantee the integrity of the OS?
Secure boot.