posted in Technology
The security co-processor in many CPUs is insecure
www.heise.de/en/news/The-security-co-processor-in-many-CPUs-is-insecure-11411956.htmlposted in Technology
The security co-processor in many CPUs is insecure
www.heise.de/en/news/The-security-co-processor-in-many-CPUs-is-insecure-11411956.htmlTrusted computing was never about security, it’s a way to take ownership of computers away from users and give it to computer manufacturers and Microsoft. It’s also not a good security model.
For #2, Full Disk Encryption (including bootloader)
My disk and bootloader are both encrypted but I can get to my UEFI menu without decrypting. I’ve been meaning to password protect that but I get nervous about changing anything in UEFI.
I didn’t know much about secure boot or TPM or PAM so I was planning on setting those up, but I’ll skip it if it’s just about corporate capture. Not that my hardware is from some big name corpo or anything, it came with linux by default. But still.
Also I’m worried about locking myself out of booting from live USBs, especially if I ever need to use a recovery drive. But I think if I understand correctly then most official ISOs should still work, but I’m not 100% certain.
Clearly, I still have a lot to learn…