Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am saying that the market for people who care about these types of things is objectively niche. Large manufacturers build what they build because they fund the research to know what to build. And they are successful at selling them because they were correct.

There might be billions of people buying computers, but the set that has any opinion on boot code signing requirements is not large enough to cause any significant impact on the market as a whole.

There are companies that cater to these niche markets, like Pine/Framework/System76/Purism. They are tiny. Dell sells more computers in a single contract than all of these other companies have sold over their entire existence combined.



True. However, sometimes large buyers, such as governments or enterprises, change their policies towards purchasing requirements. For example, since 2013 France has had an Inter-Ministry Foundation of Free Software[0], which provides the preferred software to be used across France's government, as French law requires preference be given to free software (logiciel libre).

What impact might occur if a government like France were to require in the future only RISC V architectures with free boot loaders, of if the US government or a large corporation required use of measured boot to see at boot-time if the boot code or subsequent OS had been compromised?

With persistent threat actors and the falling price of processing power, I wouldn't be surprised if in the next ten years some larger organizations (or tens of thousands of small businesses) start demanding this kind if IT security from their vendors.

[0] (in French, of course) https://sill.etalab.gouv.fr/fr/software and their repo, https://github.com/disic/sill.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: