"During the seven-second boot time, the firmware loads a series of kernel modules, all of which are signed; if the signature check fails at any point in boot-up, the machine will prompt the user for a reboot, after which a clean version of the OS is downloaded and the entire device is essentially re-imaged."