Fedora reexamines "trusted boot"
Fedora reexamines "trusted boot"
Posted Jul 1, 2011 14:16 UTC (Fri) by nix (subscriber, #2304)In reply to: Fedora reexamines "trusted boot" by Cyberax
Parent article: Fedora reexamines "trusted boot"
Right. So the former mode is fine -- but as far as I can see doesn't really need more hardware support than a bit of NVRAM. The latter mode, which actually requires crypto and so on, is as far as I can see evil, because it locks keys up in opaque and failure-prone hardware, thus effectively doing a delayed deletion on any data secured by it and a delayed DoS on any access granted by it (because hardware always fails in the end).