|
|
|
|
|
by AnthonyMouse
370 days ago
|
|
> What if you need to update the bootloader? Then you boot the system from the existing bootloader, causing the booted system to be trusted to supply a new hash. > TPMs can do remote attestation without signatures just fine, by measuring the hash of the bootloader. If there are no private keys in the TPM from the factory then there is nothing for a third party to force you to sign the hash with, as intended. |
|
All TPMs have private keys from the factory. They're entirely unrelated to the secure boot keys.