5 ms·
Suppose that a portable computer uses full disk encryption. On boot it requires a long passphrase, or requires a short passphrase and connects to a remote serve
by zrm 2y ago
Suppose that a portable computer uses full disk encryption. On boot it requires a long passphrase, or requires a short passphrase and connects to a remote server to supply a long decryption key but the remote server rate limits attempts. Either of these are rare because the system is normally on or in suspend rather than being cold booted, and once on the operating system rate limits local unlock attempts.
What is the TEE supposed to buy you over this? Avoiding the negligible inconvenience of typing the long passphrase once a month if you don't have a remote server, which the enterprises that demand features like this would have? That seems like more of a solution in search of a problem and in any event not worth the cost in authoritarianism.
Not only that, the TEE solution is less secure. If the device is stolen and you revoke access on the remote server then there is no way for an attacker with only the device to get the key. If the key is in a TPM on the device they can stick the device in a drawer and wait until someone finds a TPM vulnerability, then unlock it.
- astrange 2y agoA boot password + disk encryption helps but a) they can attack it before it reboots. b) most of the value is in the parts, so they don't need your data. You need to make the parts useless for repairs so it's not worth stealing it.
- zrm 2y ago> they can attack it before it reboots. But they can do that anyway? If they would guess your password or exploit your OS from the lock screen then they get access to your files even if the running OS is the one certified by the hardware. > most of the value is in the parts, so they don't need your data. You need to make the parts useless for repairs so it's not worth stealing it. Putting aside that "make the parts useless for repairs" is an obvious misfeature that will be used against you by the manufacturer, it's also orthogonal to boot loader signing etc. Making the parts "useless for repairs" would also be better achieved by making new and used repair parts available for competitive prices, driving down the cost of repairs to the point that stealing devices for repair parts isn't a lucrative endeavor. For example, make sure that traded-in devices never get crushed if they could be scavenged for parts to be sold into the repair market, providing a plentiful supply of used parts instead of making them scarce enough to be worth stealing.