On Mon, 4 Aug 2014 06:59:57 -0400, Peter Johansson wrote: :: The solution is to implement a proper trust model for USB devices in :: your operating system. This would include the BIOS for devices :: accessible through it at boot time I assume this is to some extent what the UEFI and certificates alleviate.=20 The problem here is that it becomes nigh on impossible to boot devices from= =20 a USB device - that is certainly the case with my Medion tablet. The only way I can use a USB stick to boot the device (for recovery=20 purposes) is to use W8.1 recovery, to install a certificate, then copy the= =20 recovery environment wim file over and rename it boot.wim. So this actually becomes an annoyance/hindrance for the user who might want= =20 security, but not as much security as public/commercial bodies may require. Colin -- cdb, colin@btech-online.co.uk on 4/08/2014 =20 Web presence: www.btech-online.co.uk =20 =20 Hosted by: www.justhost.com.au =20 =20 This email is to be considered private if addressed to a named individual= =20 or Personnel Department, and public if addressed to a blog, forum or news= =20 article. =20 =20 =20 ... --=20 http://www.piclist.com/techref/piclist PIC/SX FAQ & list archive View/change your membership options at http://mailman.mit.edu/mailman/listinfo/piclist .