Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

According to [1],

> "At boot time, a unique kernel is built and installed for the next boot"

Therefore, if the building code is itself trusted it can make a checksum and sign it. So each boot can verify the next boot, in a blockchain-ish way.

[1]: https://news.ycombinator.com/item?id=14711983



How does this help though?

If you are in a position to replace the kernel, can't you also replace the code that does this verification?

That is exactly how games are cracked, as I understand.


No, because the code doing this verification is also checked by the loader, which is checked by the secure boot module. The secure boot module provides the trust root.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: