Didier Kryn writes:
> I've read previously on this list that secureboot doesn't
> prevent booting from a usb key... Or did I misunderstood?
People spread too much FUD.
Various people have asserted, without naming names, that some/most vendors
do not allow you to delete keys from the list of accepted keys. If you can
control the list of keys, and your own key is the only one you accept, then
you can prevent booting from USB sticks.
(I won't post any more in this thread now; nothing new is going to be said
anyway. Sigh.)
Arnt