4 ms·
It doesn't have to be 64 bits passphrase. You can implement this as TOTP. Look at heads.
by bubblethink 2y ago
It doesn't have to be 64 bits passphrase. You can implement this as TOTP. Look at heads.
- freedomben 2y agoThen we have to implement TOTP (which requires a clock) in firmware. Complexity just exploded
- bubblethink 2y agoI think that is nothing compared to what modern UEFI does. There are entire hardware drivers in UEFI. To protect against software evil maid attacks, you need to authenticate the device before you use it. So it has to be some type of challenge response protocol. It can be achieved with fido type keys or it can be HOTP/TOTP.
- freedomben 2y agoFair point, we're already at the level of near full OS in the UEFI. Odds are good there's already full clock and crypto libs, so maybe it's not that much of an addition.
- deleted 2y ago[deleted]