Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

According to [1],

> "At boot time, a unique kernel is built and installed for the next boot"

Therefore, if the building code is itself trusted it can make a checksum and sign it. So each boot can verify the next boot, in a blockchain-ish way.

[1]: https://news.ycombinator.com/item?id=14711983



How does this help though?

If you are in a position to replace the kernel, can't you also replace the code that does this verification?

That is exactly how games are cracked, as I understand.


No, because the code doing this verification is also checked by the loader, which is checked by the secure boot module. The secure boot module provides the trust root.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: