Comment by saurik

6 days ago

The described mechanism doesn't say the hardware features can't assert the software features, only the other way around: the premise was merely that the software features need to be replaceable; in fact, this is exactly what you want, as it ensures that the mechanism in the hardware providing the secure boot feature is open source and it also ensures that the operating system you run is anything you want, rather than being locked into a specific choice by the maker of the hardware (or, if the people who make the hardware want to ship an OS with the hardware as if it were some kind of cohesive product, then that OS would also have to be open source and modifiable, which is how you can get a GrapheneOS in the first place).