GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Jarkko Sakkinen (jarkko@social.kernel.org)'s status on Monday, 04-Dec-2023 13:22:45 JSTJarkko SakkinenJarkko Sakkinen

    James Bottomley posted new version of the #HMAC encryption patches for #TPM2: https://lore.kernel.org/linux-integrity/20231127190854.13310-1-James.Bottomley@HansenPartnership.com/T/#t

    I spent some time refactoring the tpm_buf changes because they were the major glitch for me in the earlier versions, and those patches have been included now to this series, which is of course great. The series is probably rather sooner than later ready for inclusion to the mainline.

    This adds up to the TPM2 sealed hard drive encryption by mitigating bus interposers by a factor. An interposer anything interface the traffic between the CPU and a discrete TPM chip (i.e. not firmware TPM).

    A bus interposer can reset a TPM and replay PCR’s as the chip returns to its initial state including PCRS. To mitigate this, kernel creates HMAC session for each TPM transaction and derives session key from the so.called null hierarchy, which essentially provides a new random seed per TPM reset.

    Therefore, interposer’s ability to reset TPM decreases because kernel will not be able to communicate with the TPM and that way indirectly a malicious act can be detected by far better chances than ever before.

    IMHO, this fits quite nicely to the stuff that #OpenSUSE and #Ubuntu have been working on lately.

    In conversationMonday, 04-Dec-2023 13:22:45 JST from social.kernel.orgpermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      [PATCH v5 00/17] add integrity and security to TPM2 transactions
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.