Hacker News new | ask | show | jobs
by bitwize 700 days ago
> Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation.

No, it's really not.

Currently Microsoft requires enrolling keys and disabling SB to be available to qualify for "Designed for Windows" branding on x86 PCs. No such requirement holds for ARM PCs, and Microsoft may remove this requirement at any time.