Hacker News new | ask | show | jobs
by tedunangst 696 days ago
How do you determine when to push the button?
3 comments

Instead, write-protect the firmware by default, and require the user to press a physical button on the back of the PC to write-enable it (for a limited duration/until the next reboot)
Any time you're reinstalling the OS and suspect the old OS had malware.

Or if you want to make it simpler, any time you're reinstalling the OS.

Once a day ought to do…