4 ms·
This is already possible and has been for some time on Linux using TPM. What is different about secure enclave, or is it just Apple lingo?
by encryptluks2 4y ago
This is already possible and has been for some time on Linux using TPM. What is different about secure enclave, or is it just Apple lingo?
- tptacek 4y agoThe Apple enclave is closer to a general-purpose computer (with a bunch of cryptographic infrastructure) than a TPM, but I think for this purpose the two concepts line up.
- geocar 4y agoI think it's a critical difference that the Apple enclave has direct access to inputs (the touchid).
- deleted 4y ago[deleted]
- mjg59 4y agoUsing the Secure Enclave allows you to tie use of the key to biometric auth (which also serves as proof of physical presence). Even if someone compromises your system, they can't SSH as you without tricking you into mashing touchID.
- alwillis 4y agoThe Secure Enclave is a dedicated secure subsystem integrated into Apple systems on chip (SoCs). The Secure Enclave is isolated from the main processor to provide an extra layer of security and is designed to keep sensitive user data secure even when the Application Processor kernel becomes compromised. It follows the same design principles as the SoC does—a boot ROM to establish a hardware root of trust, an AES engine for efficient and secure cryptographic operations, and protected memory. From "Apple Platform Security"—https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/web https://support.apple.com/guide/security/secure-enclave-sec5...
- geocar 4y agoThey're not the same. The TPM chip is really just another little computer your main computer talks to over a special network; it has no access to the rest of your computer hardware, so when you type your pin or passphrase in, your computer needs to put it in memory and send it to your TPM chip over this special network cleartext. The touchid interface is part of the secure enclave packaging, so the activation command (fingerprint, nearby hotdog, whatever you've trained the sensor with) isn't ever in memory. This difference makes attacking keys stored in the secure enclave a lot harder than attacking keys stored in TPM, because with TPM, you have this second thing to attack (the cleartext channel) but with secure enclave you don't. If you want to do this on Linux, you can get bluetooth fido2 apps for your phone which work pretty well, but bluetooth is very complicated and Linux doesn't have good support for pre-login bluetooth setup afaik, so (re)provisioning can be tricky. I like these little USB-attached smart-card readers with integrated PIN-pads (either on the reader or on the card itself) because USB seems a little bit more reliable, but you may need one that also supports bluetooth or NFC in order to use your token (easily) with mobile devices if you like to login from your phone sometimes.
- yunohn 4y agoCould you point me to an easy-to-use Linux app that handles SSH keys on TPM for me? Would love to use it on my non-Mac devices.
- halz 4y agoPerhaps tpm2-pkcs11 and its ptool are approachable enough? https://github.com/tpm2-software/tpm2-pkcs11/blob/master/docs/SSH.md https://github.com/tpm2-software/tpm2-pkcs11/blob/master/doc...