6 ms·
What alternative to a users passwords do you have in mind? The only other potential cryptographically secure alternative might be a TPM chip, if a machine has
by sp1rit 5y ago
What alternative to a users passwords do you have in mind?
The only other potential cryptographically secure alternative might be a TPM chip, if a machine has this. However since a TPM stores secrets system wide, keyrings for each user seam unfeasible and it's likely less secure since you could just boot into single user mode and get the TPM secrets.
Additionally I tend to not trust the TPM (esp. on Linux), because if one firmware update somehow fails to apply properly, I'll have a far more nastier time (since all secrets are gone) than GNOME Shell promoting me to insert my old password.
- yrro 5y agoI really don't know, to be honest. TPM is one option. They should be pretty reliable--if not then you'd have Windows users kissing their encrypted disks goodbye, right? Another option (in my case) would be using FreeIPA's vault service to stash the key. It would be pretty easy for malware to grab the key though. Perhaps some setup where both a key owned by the user and a key owned by the host, with access mediated by sssd could be designed... (And admittedly for AD users it's no good since they can't use the vault service...) It feels like AD is missing some kind of secret storage service for users to make use of.