It's worth noting that System Transparency is a multi-year effort to bring transparency to running computer systems. We are aiming for what we call transparent servers. Just like there's open source software and open source hardware we think there should be open source running systems. That's the gist of it. If you think this is interesting I can highly recommend you check out Sigsum - our transparency log design for…
That said, solving a trusted boot problem was not something I could tackle alone. I didn't have a sense for how much/little I could trust the machine/bios/firmware. None of the tooling I considered (hashing firmware/boot data/etc.) seemed secure without a whole additional infrastructure.
I'm thrilled to see this implemented though.
[1] modern version here: https://github.com/joelandman/nyble