> One should be able to tell the kernel that the nVidia key can only sign the nVidia module, and to refuse anything else it signed...
Couldn't a compromised / hostile nVidia just creat a module that was called nvidia.ko, but did *bad thing*? Presumably one can't specify the allowed interfaces a module may use in advance.