!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

123 Members
44 Servers

Load older messages


SenderMessageTime
26 Jan 2024
@elvishjerricco:matrix.orgElvishJerriccoso, I don't understand how that works23:02:36
@raitobezarius:matrix.orgraitobezariusYeah so my point is really only about the fact you are moving the key to another server23:02:41
@5m5z3q888q5prxkg:chat.lightnovel-dungeon.deShane on Conduit.rs ⚡️ and Fractal 🦀️ joined the room.23:02:30
@elvishjerricco:matrix.orgElvishJerriccoohhhh23:02:50
@elvishjerricco:matrix.orgElvishJerriccook I forgot about that part23:02:57
@raitobezarius:matrix.orgraitobezariusAnd you can control removing access to that encryption key remotely23:03:09
@elvishjerricco:matrix.orgElvishJerriccoright23:03:17
@raitobezarius:matrix.orgraitobezariusAnd of course you have activity log etc23:03:19
@raitobezarius:matrix.orgraitobezariusIt becomes interesting for ONE aspect23:03:26
@raitobezarius:matrix.orgraitobezariusImagine you bind against more PCRs23:03:35
@elvishjerricco:matrix.orgElvishJerriccoso you basically are using the TPM just for remote attestation23:03:38
@raitobezarius:matrix.orgraitobezariusAnd then on a reboot something change23:03:42
@elvishjerricco:matrix.orgElvishJerriccowhich authenticates the machine to gain access to its disk decryption key23:03:51
@elvishjerricco:matrix.orgElvishJerriccofrom a server23:04:00
@raitobezarius:matrix.orgraitobezariusYou can prompt yourself on your phone or something to accept/refuse that new change, etc.23:04:02
@raitobezarius:matrix.orgraitobezarius
In reply to @elvishjerricco:matrix.org
so you basically are using the TPM just for remote attestation
Correct
23:04:09
@elvishjerricco:matrix.orgElvishJerriccoyea, that's really cool23:04:12
@elvishjerricco:matrix.orgElvishJerriccoI really like the idea of having it ping my phone too23:04:20
@elvishjerricco:matrix.orgElvishJerriccobecause if I tie the secret to the phone somehow, then it's still manually authenticated23:04:38
@raitobezarius:matrix.orgraitobezariusYep, I really want this prompt mechanism 23:05:05
@elvishjerricco:matrix.orgElvishJerriccobut it's just one convenient button press23:05:07
@elvishjerricco:matrix.orgElvishJerriccoyea23:05:12
@elvishjerricco:matrix.orgElvishJerriccoI like it23:05:13
@raitobezarius:matrix.orgraitobezariusAnd technically you can hold the encryption key in your phone's TPM223:05:17
@elvishjerricco:matrix.orgElvishJerriccotwo way remote attestation? :P23:05:34
@raitobezarius:matrix.orgraitobezariushttps://github.com/ANSSI-FR/ultrablue was so close :>23:06:04
@raitobezarius:matrix.orgraitobezariusI am still thinking of forking it and finishing the work23:06:16
@elvishjerricco:matrix.orgElvishJerriccooh yea, I forgot to look into that23:06:21
27 Jan 2024
@fractivore:cyberia.club@fractivore:cyberia.club joined the room.00:27:43
@lehmanator:gnulinux.club@lehmanator:gnulinux.club removed their profile picture.16:58:55

Show newer messages


Back to Room ListRoom Version: 6