I just hope there will be (at least) a motherboard jumper to disable it. On by default is okay (and perhaps the dist guys could publish their own certificates for inclusion in the BIOS).
Posted Sep 22, 2011 5:12 UTC (Thu) by ringerc (subscriber, #3071)
[Link]
Jumpers cost money and are unsuitable for compact PCs, laptops, etc.
Expect a BIOS/UEFI setup option to turn it off, with optional password protection to keep those pesky corporate users from installing their "hide my facebook activity" nasties even when they have physical access.
So long as I can turn it off, I'll be *happy* to see this out there. Anything that improves Windows security without preventing me from controlling the hardware I own is just fine by me. As a bonus, being able to add my own keys would let me roll out signed kernels for my servers, which would be just lovely.