Hacker News new | past | comments | ask | show | jobs | submit login

You can pretty easily sign your own kernel, it's not just manufacturer discretion.



Yeah, it's the same as SELINUX - layers of security.

I could easily see reasons to have a box that can boot a signed kernel but the signing keys are held by me offline.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: