!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
26 Jan 2024
@raitobezarius:matrix.orgraitobezariusAnd of course you have activity log etc23:03:19
@raitobezarius:matrix.orgraitobezariusIt becomes interesting for ONE aspect23:03:26
@raitobezarius:matrix.orgraitobezariusImagine you bind against more PCRs23:03:35
@elvishjerricco:matrix.orgElvishJerriccoso you basically are using the TPM just for remote attestation23:03:38
@raitobezarius:matrix.orgraitobezariusAnd then on a reboot something change23:03:42
@elvishjerricco:matrix.orgElvishJerriccowhich authenticates the machine to gain access to its disk decryption key23:03:51
@elvishjerricco:matrix.orgElvishJerriccofrom a server23:04:00
@raitobezarius:matrix.orgraitobezariusYou can prompt yourself on your phone or something to accept/refuse that new change, etc.23:04:02
@raitobezarius:matrix.orgraitobezarius
In reply to @elvishjerricco:matrix.org
so you basically are using the TPM just for remote attestation
Correct
23:04:09
@elvishjerricco:matrix.orgElvishJerriccoyea, that's really cool23:04:12
@elvishjerricco:matrix.orgElvishJerriccoI really like the idea of having it ping my phone too23:04:20
@elvishjerricco:matrix.orgElvishJerriccobecause if I tie the secret to the phone somehow, then it's still manually authenticated23:04:38
@raitobezarius:matrix.orgraitobezariusYep, I really want this prompt mechanism 23:05:05
@elvishjerricco:matrix.orgElvishJerriccobut it's just one convenient button press23:05:07
@elvishjerricco:matrix.orgElvishJerriccoyea23:05:12

Show newer messages


Back to Room ListRoom Version: 6