I wrote an article about best practices (including travel tips) for PureBoot, @purism 's tamper-evident boot firmware that allows the user to control all of the keys and secrets used for the signing process. Check it out here:

I've gotten some questions about Packagekit and why we don't provide interactive signing during package updates. I talk at length about some of the challenges with that approach here:

@kyle @purism firstly I saw Purism, then PureOS, then now PureBoot. Nice, people, and thanks @kyle for this article.

