Toot

Written by Fluchtkapsel on 2025-01-18 at 10:15

@kernellogger Wow, great overview! Thanks for sharing, I learned a lot again.

On my previous installation, Fedora Silverblue 39, I experimented with automatic TPM2 unlock and had some heated discussions in my team. But that it's even worse I didn't anticipate.

At the moment I use FIDO2, and I guess a similar attack might be feasible if the attacker could get hold of my hardware token as LUKS only checks for presence. I believe my token does not support unlocking with PIN entry that I could at least use with TPM2.

=> More informations about this toot | View the thread | More toots from fluchtkapsel@nerdculture.de

Mentions

=> View kernellogger@fosstodon.org profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113848833826122302
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
227.381853 milliseconds
Gemini-to-HTML Time
0.36551 milliseconds

This content has been proxied by September (ba2dc).