|
|
|
|
|
by throwaway7679
252 days ago
|
|
The ideal is the owner being able to use TPM/SecureBoot/etc to ensure that the device is in the configuration they want. That means resisting tampering, and making any successful tampering become obvious. The problem is third parties using TPM/SecureBoot/etc as a weapon against the owner via remote attestation, by preventing them from configuring their own device, with the threat of being cut off from critical services. Having the upside without the downside would be nice, but how could it work? Is a technical solution feasible, or would it need a law/regulation? |
|