

I don’t think it’s a question of willingness to understand, but one of disagreement about the seriousness of the problem. Not to mention the implict idea that a “verified boot” is the only way to get that result. E.g. it’s very easy to get to a “safe factory state” without that kind of locking, for example with an immutable boot loader, as is typically present in many ARM SoCs (Allwinner, Rockchip, …). In that case you can revert to a safe state by downloading a known good OS image (using a trusted machine) and installing that image using only the immutable bootloader.







If you find a solution, please let us know. I’m suffering from the same problem with my 2017 X1 Carbon