4 ms·
Yes exactly. You'd enter your password once at boot. Then the OS remembers whatever key it needs to access your keychain. The OS becomes the arbitrator to allow
by captainmuon 3y ago
Yes exactly. You'd enter your password once at boot. Then the OS remembers whatever key it needs to access your keychain. The OS becomes the arbitrator to allow who accesses the keychain.
Similar to how BitLocker works, I assume. Windows has the keys to decrypt the hard disk, but it requires a valid login + the TPM to actually give it out.
I'm not a crypographer so I won't claim to know details, but I think there are schemes to keep secrets safely encrypted in RAM, and only when the OS says OK it uses the TPM do decrypt the secrets.
This fails of course when there is a bug in the OS, you can manipulate the CPU directly, or get between the CPU and the TPM, but then we are in "other side of the airtight hatchway" land anyway. I mean it is always a matter of what is my threat scenario, and what level of comfort do I want.