| ▲ | naturalmovement 2 hours ago | |
> Secure boot is designed to verify software signatures aka integrity. HTTPS is a useless gesture here, adding complexity to critical software that needs to be as simple and auditable as possible. Confidentiality is essentially unimportant to anyone but the most autistic of by-the-book nerds. It buys you nothing in a practical sense. Most netbooting happens over closed networks anyway. | ||
| ▲ | robertlagrant 2 hours ago | parent [-] | |
I agree that integrity can be done by secure boot, but HTTPS does mean that someone can't intercept your request and serve you valid, signed, older software that has a known security flaw in it. | ||