programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002 to Linux · 28 days ago

Protecting against rogue devices with Full Disk Encryption and TPM

news.opensuse.org

external-link
message-square
6
link
fedilink
  • cross-posted to:
  • [email protected]
51
external-link

Protecting against rogue devices with Full Disk Encryption and TPM

news.opensuse.org

cm0002 to Linux · 28 days ago
message-square
6
link
fedilink
  • cross-posted to:
  • [email protected]
Fde Rogue Devices
news.opensuse.org
external-link
Protecting against rogue devices in openSUSE with Full Disk Encryption openSUSE have now multiple ways to configure a Full Disk Encryption (FDE) installation...
alert-triangle
You must log in or register to comment.
  • uawarebrah@sh.itjust.works
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    27 days ago

    Linux still needs some work in this space, we need full verified boot and ways to protect the boot partition against evil maid attacks. This is one major reason I haven’t been able to fully switch to Linux.

  • thann@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    2
    ·
    27 days ago

    UEFI is the problem, we need coreboot!

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      26 days ago

      Tianocore is the foss implementation

  • Björn Tantau@swg-empire.de
    link
    fedilink
    arrow-up
    2
    ·
    27 days ago

    Can someone ELI5? Do I have to do something when I just use FDE with a passphrase?

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      26 days ago

      You can use TPM2 on Linux but it can have some bad security consequences if done incorrectly.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    26 days ago

    Interesting

    Secure boot is very hard to get right. At Tue moment I would be hesitant to rely on it solely.

Linux

linux

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • [email protected]
  • [email protected]
  • Matrix instant messaging group chat

Original icon base courtesy of [email protected] and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 646 users / day
  • 1.96K users / week
  • 4.17K users / month
  • 10.1K users / 6 months
  • 1.8K local subscribers
  • 8.95K subscribers
  • 2.42K Posts
  • 17.7K Comments
  • Modlog
  • mods:
  • Ategon
  • adr1an
  • dwraf_of_ignorance
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org