Hacker News new | ask | show | jobs
by tstack 206 days ago
> There's also a new "https boot", which is supposed to be a PXE replacement, but TLS certs have time validity windows, and some clients may not have an RTC, or might have a dead CMOS battery, and those might not boot if the date is wrong.

I think the lack of entropy right after boot can also be a problem for the RNG. But, maybe that has been solved in more modern hardware.