Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Surely the answer is to sign distributions (or not) as verified as originating from a domain (eg microsoft.com), then let the user choose which os to boot in the bios (or whatever becomes). Then if you want to run an os from an untrusted domain you can, or you can just stick to whatever is sighed as coming from microsoft

As far as I can see all pc manufacturers would need to do is verify the certificate of each os on an os selection screen and display the result to the user



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: