3 ms·
TPM chips are specifically designed so that what you're suggesting won't work. Their PCR registers (Platform Configuration Registers) act as sort of tripwires
by dinom 4y ago
TPM chips are specifically designed so that what you're suggesting won't work.
Their PCR registers (Platform Configuration Registers) act as sort of tripwires so that the boot chain isn't "locked down" but "measured". Each step of the boot chain updates a register with it's own hash that's hashed with the prior step's hash. What a tangled web, huh?
That way, if you're sealing your data to the appropriate PCR registers, the data won't be able to be retrieved if any part of the boot is changed... e.g. usb device plugged in or kernel/grub parameters changed.
In addition, TPM chips are "married" to the computers they're plugged into. Once you remove a TPM and put it in a different computer it will reset itself.
I just did a fairly deep dive into all this getting a machine up and running for co-location. Coincidentally, I just posted a "Show HN" here...
https://news.ycombinator.com/item?id=35066894 https://news.ycombinator.com/item?id=35066894