Hacker News new | ask | show | jobs
by xenadu02 2032 days ago
The easy path on M1 would have been to lock everything down. Use the same iBoot phones use, the same kernel configuration, and call it a day.

It takes a lot of engineering work to make more permissive security modes work. To re-architect booting. To make external drive booting work. To make developing kernel extensions on production systems work. To allow signing your own boot blob. Work that 99% of users don't even understand let alone care about.

If that isn't enough evidence then nothing ever will be.