4 ms·
I have long advocated for disabling tpm in bios, uefi-boot raw dm-crypt to even get grub much less init. This is also how I have done encrypted disks in the clo
by temp_gnuser 3y ago
I have long advocated for disabling tpm in bios, uefi-boot raw dm-crypt to even get grub much less init. This is also how I have done encrypted disks in the cloud using dropbear ssh as an initram shim for key/pass entry. Bios boot pass is annoying but required. Watch your acess/auth logs. Run a HIDS. Isolate your procs and especially their network comms. Security is an onion, not that most c-suites have any idea these days, blinded by fast talkers.
- jiveturkey 3y agoif security is an onion, why do you advocate for throwing the baby out with the bathwater?
- temp_gnuser 3y agoCould you be more specific please?
- CoolCold 3y agoWhat's your way of providing laptops to your employees? For simplicity, let's assume everyone is located in the same country.
- temp_gnuser 3y agoSetup in house via imaging then control once vpn is established via cac tooling. I've run all linux laptop fleets this way before so it does work but I have some ideas on improvement. PXE is a weak protocol in the stack for example.