Hacker News new | ask | show | jobs
by blueflow 708 days ago
> The boot loader signing aspects were always for control and restricting devices

Not surprising, given the huge role Microsoft had in developing this.

You can't enroll your MOK without booting up, and you can't boot up if Microsoft hasn't signed your bootloader/kernel... It used to be an no-brainer and now its difficult.