!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

183 Members
52 Servers

Load older messages


SenderMessageTime
3 Jan 2025
@elikoga:matrix.orgelikoga changed their display name from elikoga (@38c3 📞488{0,1,9}) to elikoga.10:28:02
12 Jan 2025
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب) joined the room.12:37:08
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)Hello, I recently got a new laptop with a modern CPU that have a TPM chip, What can I do with it to improve the security of my system?12:45:10
@elikoga:matrix.orgelikoga
In reply to @nakibrayane:matrix.org
Hello, I recently got a new laptop with a modern CPU that have a TPM chip, What can I do with it to improve the security of my system?

https://jnsgr.uk/2024/04/nixos-secure-boot-tpm-fde/

You can use it to unlock your encrypted disk without user intervention

14:59:17
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)How is this more secure then dm-crypt with a password, If someone store my laptop, they can just assess all the data in it.16:30:53
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)* How is this more secure then dm-crypt with a password? If someone store my laptop, they can just assess all the data in it.16:31:34
@elikoga:matrix.orgelikoga

No? I hope you have your user account protected with a password.

The tpm will not release your encryption keys if system integrity is not given. For example my laptop tpm locks if you open the chassis

16:31:58
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)So they can't just put the hard disk in another PC, My hard disk will only unlock in my laptop. And then the security of my data is protected with userspace programs (e.g. GDM, tty login), Is this correct?16:34:29
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)And is this more secure then dm-crypt?16:34:38
@elikoga:matrix.orgelikogaIn combination with dmcrypt it is in my opinion more secure since you don't need to input an encryption key by hand16:35:17
@elikoga:matrix.orgelikoga Or luks/dmcrypt not sure what the delineation is exactly 16:35:33
@elikoga:matrix.orgelikoga
In reply to @nakibrayane:matrix.org
So they can't just put the hard disk in another PC, My hard disk will only unlock in my laptop. And then the security of my data is protected with userspace programs (e.g. GDM, tty login), Is this correct?
I think that's correct
16:35:47
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)But if there is a bug with GDM, they would get access to my computer, I think that dm-crypt have is more secure. 16:37:55
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)But the convenience of having one password is also nice.16:38:20
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)* But if there is a bug with GDM, they would get access to my computer, I think that dm-crypt is more secure. 16:38:42
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)Can I use the TPM to generate random numbers in /dev/random, instead of using software solutions to do that?16:42:17
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)* Can I use the TPM to generate random numbers for /dev/random, instead of using software solutions to do that?16:43:03
@elikoga:matrix.orgelikogaUnless you disable it in the kernel, this is already the case: https://github.com/torvalds/linux/blob/b62cef9a5c673f1b8083159f5dc03c1c5daced2f/drivers/char/tpm/Kconfig#L44-L5316:59:23
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)I will see if I stick with my setup or switch to using TPM, Thank you for your help :017:01:05
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)* I will see if I stick with my setup or switch to using TPM, Thank you for your help :)17:01:08
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب)* I will see if I stick with my setup or switch to using TPM to decrypt encryption, Thank you for your help :)17:04:15
17 Jan 2025
@hexa:lossy.networkhexahttps://oddlama.org/blog/bypassing-disk-encryption-with-tpm2-unlock/15:44:06
19 Jan 2025
@thebus:matrix.orgJaco joined the room.14:49:49
21 Jan 2025
@joelmatrixaccount:matrix.orgJoel joined the room.12:10:49
27 Jan 2025
@brisingr05:matrix.org@brisingr05:matrix.org joined the room.02:49:12
30 Jan 2025
@laurynasp:matrix.orglaurynasp joined the room.08:54:55
2 Feb 2025
@pederbs:pvv.ntnu.nopbsds changed their display name from pbsds to pbsds (FOSDEM).16:04:37
3 Feb 2025
@pederbs:pvv.ntnu.nopbsds changed their display name from pbsds (FOSDEM) to pbsds.16:25:07
7 Feb 2025
@diamondburned:matrix.orgdiamond (it/its) changed their profile picture.23:10:27
@diamondburned:matrix.orgdiamond (it/its) changed their profile picture.23:18:55

Show newer messages


Back to Room ListRoom Version: 6