Remix.run Logo
Dylan16807 16 hours ago

If we pretend we're revising TFTP boot in 1995, let's have it get up to 20 boot options from the server and their md5 hashes, and if it's not set to auto it waits for the user to pick one. It then verifies the hash as it downloads. Also it uses TCP for the download.

Joker_vD 14 hours ago | parent [-]

Nah, you won't sell the cow like that. You need to add more reliance on the public CA infrastructure and third-party code signing. Also, "ask user"? Ask the TPM instead — I mean, why would the computer's owner trust the computer's user, right?