|
|
|
|
|
by AnthonyMouse
370 days ago
|
|
How is it any different? You install the hash of the boot loader when you issue the machine, then use the trusted system to update the hash if necessary. Also, the concern is that the system comes from the factory with private keys the owner doesn't have access to, allowing the device to defect by informing on them to a third party. Keys installed by the owner rather than the manufacturer are fine, and then such keys also wouldn't be trusting random third party code either. |
|
With your private CA you can skip the "update the hash" part, removing a crucial step that one might forget in a hurry or that simply might go wrong because of whatever sort of bug or power outage... and brick thousands of machines as a result.