Hacker News new | ask | show | jobs
by pabs3 382 days ago
Have you considered using dm-verity instead of signed binaries?
1 comments

> Have you considered using dm-verity instead of signed binaries?

Why? I don't see any benefits.

In any case, the developers don't get a say in what is used to secure the terminal. The manufacturer decides that, then they get the hardware+firmware certified.

The terminals the developers get are already certified and locked down.

Authenticating the block device before it reaches the Linux kernel filesystem code.