!BgJZHVOYkwVcEKLAyM:nixos.org

NixOS Deployments

1248 Members
NixOS Deployment tooling307 Servers

Load older messages


SenderMessageTime
2 Sep 2021
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️I hate it when consumer hardware is locked down compared to enterprise11:29:01
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️
In reply to @manveru:matrix.org
with TPM it'd be much nicer too... but those are VMs :(
Wait, can't VMs expose an emulated TPM device that would be as trustworthy as the VM host?
11:29:36
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️That would be useful if the host is trustworthy (and if not, you're screwed anyway)11:29:55
@manveru:matrix.orgmanveruthat'd be nice, but i have no control over that part...11:30:09
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️Cloud hosting?11:30:37
@manveru:matrix.orgmanverucan't really talk about that part ^^;11:31:25
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️

It's ok, we all have secrets :3

I wish I had a working TPM in my laptop. My UEFI implementation seems so broken that the ACPI stuff breaks the TPM support in Linux

11:32:00
@manveru:matrix.orgmanveruthat sucks :(11:32:20
@manveru:matrix.orgmanverui have TPM, but unfortunately it doesn't have ed25519 support...11:32:46
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️I kinda want to lock SSH host keys to TPM and unseal them on Secure Boot authentication, and then unseal secrets on the host keys as the identity of the machine11:33:08
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️Sadly Raspberry Pi doesn't have secure boot (but can have a TPM via an external device)11:33:42
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️I am sure though that I can seal the TPM to different PCRs representing something different11:34:03
@manveru:matrix.orgmanveruyep, that's definitely my ideal setup too, it's just so hardware dependent to be hard to generalize...11:34:12
@grahamc:nixos.org@grahamc:nixos.org No tpm has ed25519 support lol 11:34:25
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️lol11:34:37
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️then it leaves an RSA key that would decrypt an ed25519 key11:35:04
@manveru:matrix.orgmanveruthe yubi hsm can do ed2551911:35:43
@manveru:matrix.orgmanverubut it's bloody expensive11:35:50
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️

.<

11:36:04
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️* >.<11:36:15
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️* \ >.<11:36:21
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️Redacted or Malformed Event11:36:25
@grahamc:nixos.org@grahamc:nixos.orgYeah but TPMs aren’t very interesting if they’re not connected directly to the CPU over that weird bus. The HSM would be interesting for other reasons though11:36:37
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️* \>.<11:36:50
@manveru:matrix.orgmanveruyeah, but as you said, RSA usually suffices with some extra steps11:37:13
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️TPM is the most interesting when it can't be intercepted11:37:27
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️So yeah, direct CPU connection11:37:37
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️I guess11:37:38
@grahamc:nixos.org@grahamc:nixos.org More importantly to me, the CPU needs to send it hashes of everything it executes starting from the firmware it uses before it turns on the real internal cores 11:39:04
@grahamc:nixos.org@grahamc:nixos.org Needs CPU and firmware cooperation 11:39:50

There are no newer messages yet.


Back to Room ListRoom Version: 6