Hacker News new | ask | show | jobs
by lelanthran 382 days ago
> Have you considered using dm-verity instead of signed binaries?

Why? I don't see any benefits.

In any case, the developers don't get a say in what is used to secure the terminal. The manufacturer decides that, then they get the hardware+firmware certified.

The terminals the developers get are already certified and locked down.

1 comments

Authenticating the block device before it reaches the Linux kernel filesystem code.