!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

175 Members
43 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@andi:kack.itandi- changed the history visibility to "world_readable" from "shared".12:07:40
@grahamc:nixos.org@grahamc:nixos.orgnice12:09:15
@grahamc:nixos.org@grahamc:nixos.orgI read a few chapters of this book, "Quick Tutorial on TPM 2.0", "Platform Configuration Registers", "Solving Bigger Problems with the TPM 2.0" but I got pretty annoyed by it early on, so I didn't read super carefully. https://link.springer.com/content/pdf/10.1007%2F978-1-4302-6584-9.pdf I watched https://av.tib.eu/media/41722, which covers the basic operations I looked at https://wiki.archlinux.org/title/User:Diabonas/Trusted_Platform_Module#Storing_secrets_in_the_TPM step 1 to play with it for real12:09:21
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels joined the room.12:09:23
@grahamc:nixos.org@grahamc:nixos.org^ recording material I looked at12:09:26
@manveru:matrix.orgmanveru joined the room.12:09:46
@andi:kack.itandi-I've found this https://kernsec.org/wiki/index.php/Linux_Kernel_Integrity12:09:54
@andi:kack.itandi-had a bunch of (somewhat dated) links12:10:00
@grahamc:nixos.org@grahamc:nixos.orgI'm still waiting for someone to confirm what I believe to be a fundamentally true security property https://developers.tpm.dev/posts/1557577412:11:22
@grahamc:nixos.org@grahamc:nixos.orgjust as many bots as people in here12:11:35
@andi:kack.itandi-I am still a bit confused by the requirement of different secrets to decrypt one secret. This is probably because TPMs support different trust roots(?) and each of the root has to match the secrets you want to decrypt?12:12:51
@grahamc:nixos.org@grahamc:nixos.orgyeah12:13:00
@andi:kack.itandi-So, why that take ownership stuff then?12:13:12
@grahamc:nixos.org@grahamc:nixos.orgyou can create a hierarchy of keys which reveal different amounts of data12:13:20
@andi:kack.itandi-Shouldn't I rather specify the root somehow?12:13:21

Show newer messages


Back to Room ListRoom Version: 6