On Di, 2018-08-07 at 15:38 +0800, Yu Chen wrote: > > As STD affects the whole machine it must require root rights. > > So I cannot see how you can talk about a session belonging > > to a user. Please explain. > > > > The case is for physical access, not the 'user' in OS. Well, yes, but Secure Boot does not guard against anybody booting or halting the machine. It limits what you can boot by a chain of trust. I think you are trying to add a feature to Secure Boot. Regards Oliver