!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

171 Members
43 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
26 Jan 2024
@elvishjerricco:matrix.orgElvishJerriccoso you basically are using the TPM just for remote attestation23:03:38
@raitobezarius:matrix.orgraitobezariusAnd then on a reboot something change23:03:42
@elvishjerricco:matrix.orgElvishJerriccowhich authenticates the machine to gain access to its disk decryption key23:03:51
@elvishjerricco:matrix.orgElvishJerriccofrom a server23:04:00
@raitobezarius:matrix.orgraitobezariusYou can prompt yourself on your phone or something to accept/refuse that new change, etc.23:04:02
@raitobezarius:matrix.orgraitobezarius
In reply to @elvishjerricco:matrix.org
so you basically are using the TPM just for remote attestation
Correct
23:04:09
@elvishjerricco:matrix.orgElvishJerriccoyea, that's really cool23:04:12
@elvishjerricco:matrix.orgElvishJerriccoI really like the idea of having it ping my phone too23:04:20
@elvishjerricco:matrix.orgElvishJerriccobecause if I tie the secret to the phone somehow, then it's still manually authenticated23:04:38
@raitobezarius:matrix.orgraitobezariusYep, I really want this prompt mechanism 23:05:05
@elvishjerricco:matrix.orgElvishJerriccobut it's just one convenient button press23:05:07
@elvishjerricco:matrix.orgElvishJerriccoyea23:05:12
@elvishjerricco:matrix.orgElvishJerriccoI like it23:05:13
@raitobezarius:matrix.orgraitobezariusAnd technically you can hold the encryption key in your phone's TPM223:05:17

Show newer messages


Back to Room ListRoom Version: 6