4 ms·
Is the dm-crypt decryption key stored on the NitroKey with a pin/passphrase to access the key to mount the decrypted the disk?
by mlosapio 7y ago
Is the dm-crypt decryption key stored on the NitroKey with a pin/passphrase to access the key to mount the decrypted the disk?
- JensRantil 7y agoFrom what I understand the key is verifying that BIOS and unencrypted part of disk is unaltered. It is not verifying that any of the encrypted part of the hard drive has been tampered with. As such, it is not storing the hard drive decryption key on the USB stick.
- josteink 7y agoSo this is much like UEFI secure-boot then?
- jans23 7y agoMeasured boot allows to verify the integrity of the installed firmware (which itself verifies the integrity of the Linux boot partition) by a separate Nitrokey. The idea is that you have your Nitrokey nearby and therefore safe against compromise, other than the laptop which may be left unattended.