For security purposes, wouldn't it be enough for the mechanism to simply display a change in the signing status, and not restrict boot? This would allow for the detection of malware without restricting how people use their hardware.
Displaying or dismissing such a notification needs to be built into the hardware in such a way that the OS wouldn't be able to interfere. There should also be a read-only channel for applications running on the OS to access the signing status to enable security programs.
Displaying or dismissing such a notification needs to be built into the hardware in such a way that the OS wouldn't be able to interfere. There should also be a read-only channel for applications running on the OS to access the signing status to enable security programs.