

In practice, Machine Owner Keys are a thing, though it depends on Microsoft still signing shim, I believe.
Having Microsoft in the chain of trust rather than a standards body is rather concerning, though.
Modern hardware absolutely should have an encryption processor; TPM just isn’t great.





The year of Linux on the desktop was the friends we made along the way…