Hacker News new | ask | show | jobs
by tomxor 2243 days ago
Hypothetical: The keys are available one way or another, now anyone can sign firmware.

... Is this even worse?

Sure we can get our SPI programmers out and be sure whats on there, but what about 99% of all other users who are now exposed not only Intels potential abuse of ME, but all vendors and anyone who intercepts devices. I obviously don't like IME/PSP but perhaps the only safe option is to push for removal not opening.

1 comments

The best option is UI for users to add their own keys.