Toot

Written by elfy on 2025-01-18 at 14:00

@kernellogger Thanks for the great article and documentation! Ironically I started fiddling with TPM-based LUKS decryption during bootup recently and I asked myself those questions (as most guides online will only suggest measuring PCR 1 and 7, e.g. when using Clevis. Which might be sufficient if the threat model is considering it secure enough).

I fear securing bootup on Linux will take years, even if the tools like systemd's features are already in place.

=> More informations about this toot | View the thread | More toots from elfy@chaos.social

Mentions

=> View kernellogger@fosstodon.org profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113849718678190214
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
224.410928 milliseconds
Gemini-to-HTML Time
0.522692 milliseconds

This content has been proxied by September (ba2dc).