fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#tpm

2 posts2 participants0 posts today

Does anyone know how persistent secrets are loaded into Windows with Virtualization Based Security? I understand how online credentials can be stored in secured memory in VTL1, but how do, for example, Windows Hello credentials get set up in VTL1 without a way to access them from VTL0?

The key material has to be on disk somewhere, which could then be encrypted by any process with access to the TPM. Is VTL1 just using the physical TPM and proxying a separate vTPM to VTL0?

Banco Central mantiene en 4% Tasa Política Monetaria por tercera ocasión

El jerarca del BCCR afirmó que una de las razones por las que se dejó la TPM en el mismo nivel es que hay muy poca transferencia de las rebajas anteriores en las tasas de interés del mercado financiero.
La entrada Banco Central mantiene en 4% Tasa Política Monetaria por tercera ocasión aparece primero en Semanar [...]

#BancoCentral #MercadoFinanciero #País #TASADEPOLÍTICAMONETARIA #TPM #ÚltimaHora

semanariouniversidad.com/pais/

Via #TalkingPointsMemo @ 5:31pm ET on Mar 07, 2025

The #Trump #WhiteHouse has taken its attempt to seize direct control over the entire #ExecutiveBranch to a new level and laid out a startling legal rationale for the move in a previously unreported email obtained by #TPM. If successful, Trump would be making a dramatic end run around the #Senate’s #AdviceAndConsent power for certain appointed positions.

#StopDictatorDon
talkingpointsmemo.com/news/exc

TPM - Talking Points Memo · EXCLUSIVE: Trump Makes Aggressive New Claim of Executive Power To Circumvent The Senate By Josh Kovensky
Reviewed this morning the latest incarnation of Trenchboot from Ross Philipson (of Oracle). salute this work in the sense that D-RTM is a hardware feature with something like 20 years of age and no success realizing in the upstream. It's pretty nasty one to get right...

https://lore.kernel.org/linux-integrity/20241219194216.152839-1-ross.philipson@oracle.com/

#linux #kernel #tpm
lore.kernel.org[PATCH v12 00/19] x86: Trenchboot secure dynamic launch Linux kernel support - Ross Philipson

Via #TPM @ 5:12pm ET, Mar 06, 2025

A federal judge ruled that President #Trump’s firing of #GwynneWilcox was unlawful and ordered her restored to the #NationalLaborRelationsBoard in an opinion that excoriated his quest to craft a new, super-powerful presidency.

“A President who touts an image of himself as a ‘king’ or a ‘dictator,’ perhaps as his vision of effective leadership, fundamentally misapprehends the role under Article II of the U.S. #Constitution"

#NLRB

talkingpointsmemo.com/news/jud

TPM - Talking Points Memo · Judge Reinstates Fired NLRB Member, Rejecting ‘A Presidency That Is Untouchable By The Law’By Kate Riga

Imaginative threat scenario:

When it comes to #SecureBoot some people don't want to enroll Microsoft keys because they are afraid it opens up the possibility of booting malicious boot environments.

My LUKS password is TPM sealed with PCR7 and requires a PIN. Microsoft keys enrolled.

You are a threat actor trying to decrypt my disk. You have managed to successfully boot a malicious initramfs and presented me with a LUKS prompt.

What do you do once I hit enter?

Literal #showerthoughts of the day: why isn't there a new boot firmware for personal computers that combines good ideas from iBoot and depthcharge, while keeping #UEFI as the interface for the OS and adding some cool extras?

  • (when preinstalled on a Product™) start out in normie mode: verified boot a stock OS; require a timed presence check or a physical jumper to Take Control and enter nerd mode
  • in nerd mode, an authenticated (configurable MFA!!) admin interface lets the user manage policies that can then be selected at boot time
  • policies are configs/scripts as simple as "boot anything from the first USB stick found" or as advanced as "ask for extra password, boot only from nvme0, verify against key X, measure to #TPM PCR Y (to allow unlocking FDE), show TPM-TOTP, and disable suspend"
  • you can have multiple policies just like on Apple silicon; each policy would have its own isolated EFI variable store (!)
  • policies are signed on the TPM (requiring admin auth to sign) and stored to NVRAM/etc., and verified every time
  • security bonus: where possible, out-of-band indication of which policy has been booted (LEDs, tiny LCDs, etc.)
  • OSdev bonus: policy checkbox that turns on… a built-in m1n1 style mmiotrace (& debug) hypervisor! (literally why the hell don't we have that everywhere?!)
  • the admin interface can be a nice GUI; it all must be written in Rust of course; and it must be like, just a payload for coreboot/PEI/etc. (reinventing early init is out of scope)

some computer company plz hire me to bring this vision to life? :3

TPM и Secure boot это полурак полухуй на десктопах

TPM более менее надёжно может защищать с PIN, но и тут есть проблемы, хер разбери у тебя на плате китайский камущек сделанный джунхуем за три копейки без защиты от tampering или что то реально рабочее, шифровуются ли линии - непонятно, куча нюансов, Проще тупо включить argon в luks и быть уверенным что так оно за себя постоит.

А Secure Boot, в каких случаях он хоть что то полезное делает вообще? Ядро повреждено вирусней и так вы в безопасности? Так тогда это уже пиздец и с компа уже все унесли.

Хрень это все вообщем, microsoft как обычно шизы
#linux #tpm #secure_boot #opsec #luks

:loading: Talking Point Memo's Josh Marshall is asking for help from US citizens in documenting town hall meetings in these united States:

"I’m trying to compile a list of all the town halls where GOP members of Congress got rocked by constituents this past week while they were on break. There are so many now that I can’t really write a whole post about each one. But I wanted to ask if you could send me links if there are examples where your member of Congress or Senator had a similar experience so I can add it to the list."
talkingpointsmemo.com/edblog/y
:loading:
#USPolitics #USGovernment #TownHalls #JoshMarshall #TPM

TPM - Talking Points Memo · Ye Olde GOP Townhall ListBy Josh Marshall