Replying to @sanitation@lemmy.today
Your mum is a rounding error.

Replying to @sanitation@lemmy.today
Your mum is a rounding error.
Replying to @beep@piefed.world
Relevant David Revoy cartoon: https://thebrainbin.org/m/comicstrips@lemmy.world/t/1848750/authenticity-problem
thebrainbin.orgauthenticity problem - Comic Strips - the/brain/binhttps://www.peppercarrot.com/en/miniFantasyTheater/064.html#bonusReplying to @Joelk111@lemmy.world
Plenty of shallow people in the world, sadly, enjoy vicariously living even shallower lives than their own.
Replying to @wreckedcarzz@lemmy.world
IPMI/BMC have been known problems since 2015, if not before.
Matthew Garrett: IPMI - because ACPI and UEFI weren't terrifying enough
YouTubeIPMI - because ACPI and UEFI weren't terrifying enoughI feel the same way, but can you explain how a VPN would help achieve that in the face of Google’s proposed developer verification scheme?
How would that help you?
The article says, "unverified apps will only be easily installable in the sanctioned countries where verification doesn’t exist."
So even if you used a VPN to trick Google into thinking you live in a sanctioned country, you wouldn't be able to distribute apps to those countries without breaking sanctions.
Replying to @return2ozma@lemmy.world
This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.
Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.
Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.
AP NewsFACT FOCUS: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidencePresident Donald Trump is claiming, without evidence, that recent cyberattacks in Minnesota were the fault of the state, including Democratic Gov. Tim Walz.Replying to @talkingpumpkin@lemmy.world
If it's a server for self hosting you definitely don't want anything that requires interaction at boot.
Depends on use-case. If you only plan to boot it when you're physically present, it's fine.
Replying to @mazzilius_marsti@lemmy.world
i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.
You're thinking of Heads, which I agree is ideal for supported motherboards.
Replying to @esc@piefed.social
tang
Thanks. TIL about Clevis/Tang.
Replying to @talkingpumpkin@lemmy.world
Yes. Here are some common self-hosting scenarios:
In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.
Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It's mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.
Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.
However, there is more than one way to do that. Hence the question in my OP.
posted in Selfhosted
Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
thebrainbin.orgUnlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP? - Linux - the/brain/binWhich approach do you think is better, and why? ...Replying to @GrapheneOS@grapheneos.social
It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
By "duress profile", I mean that if user has enabled a "duress profile" feature in Settings, then entering the duress PIN would:
So, how would forensic software detect that the unlocked profile is a duress profile?
GrapheneOS MastodonGrapheneOS (@GrapheneOS@grapheneos.social)17.9K Posts, 0 Following, 38K Followers · Open source privacy and security focused mobile OS with Android app compatibility.Replying to @Semi_Hemi_Demigod@lemmy.world
@GrapheneOS everyone seems to be clamouring for the same thing: add "duress profile" to the roadmap. Keep up the good work.
GrapheneOS MastodonGrapheneOS (@GrapheneOS@grapheneos.social)17.9K Posts, 0 Following, 38K Followers · Open source privacy and security focused mobile OS with Android app compatibility.