4 ms·
You could bind your disk unlock to also include a PIN entered at boot-time (TPM+PIN). This gives you the benefit of system integrity verification at time of bo
by g_p 3y ago
You could bind your disk unlock to also include a PIN entered at boot-time (TPM+PIN).
This gives you the benefit of system integrity verification at time of boot, but also requiring your input to release the keys (and meaning you can't get to the system lock screen without the PIN).
- 542458 3y agoSide note, does anybody know why TPM schemes use a numeric PIN for pre-boot unlock rather than a full alphanumeric password? For a given length (say, 8) a password would presumably be more secure than just a PIN. It’s not like this is a phone where you need users to be able to quickly enter the code on a limited input surface.
- Foxboron 3y agoThere is no limit to the password. Usinging a 4 digit numeric PIN is just easier to remember, and because of the bruteforce resistance it doesn't decrease the security.
- alex7734 3y agoIf you're going to use a long password there is no point to using the TPM as the length of the password itself is enough brute force resistance.
- SV_BubbleTime 3y agoSome you know + something you have/are?
- alex7734 3y agoI don't think it is that much more secure, given that in this case "something you have" is bolted onto the machine you're attempting to protect and that a sufficiently long password provides enough space to make brute forcing impossible anyway. In my opinion all the TPM achieves in this case is ensuring you lose your data if the machine dies (or if some OS update fucks up and doesn't properly ensure the TPM acknowledges the new version as valid). That said it does help against the so called evil maid attacks, given that it would lock itself out if anyone modifies the OS, so if that's part of your threat model then it is useful, I guess.
- bootsmann 3y agoEven with a TPM the disk is still fundamentally encrypted with a key that you can make a copy off and put in your drawer for recovery purposes. It just offers a way to do FDE with no or just a low entropy passcode. This protects against most data loss incidents (laptop getting stolen) without producing massive overhead.
- dist-epoch 3y ago> rather than a full alphanumeric password Because there are different kinds of keyboards out there, with different layouts, so if you switch keyboard you could find yourself unable to input the password. Imagine typing a "non-English" letter in the password and then switching to a US layout keyboard without that letter. Sure, a rare scenario, but with hundreds of millions of users you will hit it.
- n_plus_1_acc 3y agoFrench keyboards have the numbers and symbols swapped. The numbers require shift.
- poettering 3y agoWith systemd you can enroll any string you want as "PIN" for tpm. There are no restrictions. Can be long, can be alphanumeric, contain weird chars, up to you.
- bootsmann 3y agoThis is just the default configuration BitLocker used for a long time, there is a no hardware constraint that causes this. However, pins are easier to remember, usually guaranteed to be available at the pre-boot time the tpm needs unlocking and as the TPM ships with anti-hammering abilities they offer sufficient entropy to protect against attacks.
- tempmac 3y agofor windows 10 pro+: you can get full alphanumeric+special_chars ONLY if you do some gpedit stuff (for win home users: regedit?)