28 ms·
Depends on the use case. If boot requires a password, the computer can never lose power or be rebooted without human presence. That’s not always practical.
by dangero 2y ago
Depends on the use case. If boot requires a password, the computer can never lose power or be rebooted without human presence. That’s not always practical.
- prmoustache 2y agoThat is what remote kvm are for and if you do that on commodity hardware you can start a tiny ssh server starting up from an initrd. Having said that an attacker with local access could change the initrd without your knowledge so that it logs the password you enter so it is not necessarily the most secure solution.
- deno 2y agoYou’ve answered it yourself. Without TPM you have no idea if you can provide the secret to the system or if it’s compromised. Whether that secret comes from TPM or network is secondary.
- tucnak 2y agoGoogle: IPMI, BMC
- teddyh 2y agoYou can reboot your full-disk-encryption server while you sleep. Obligatory plug: <https://www.recompile.se/mandos https://www.recompile.se/mandos> Disclosure: I am a co-author of Mandos.
- prennert 2y agoHas this solution been audited? In particular, is it safe to replay attacks by actors listening in to the network traffic? Also from the diagram it looks like the secret key is stored unencrypted on the server, or do I read it wrong?
- teddyh 2y ago> Has this solution been audited? Only insofar as everybody that I’ve asked over the years has failed to find anything wrong with it. But no formal verification has been done. > In particular, is it safe to replay attacks by actors listening in to the network traffic? Yes, it is safe, since we make sure to only use TLS with PFS. > Also from the diagram it looks like the secret key is stored unencrypted on the server, or do I read it wrong? No, the secret is stored encrypted on the server, encrypted with a key which only the client ever has. For more information, see the introduction and FAQ: <https://www.recompile.se/mandos/man/intro.8mandos https://www.recompile.se/mandos/man/intro.8mandos>
- deleted 2y ago[deleted]
- gerdesj 2y agoThank you for this. I will almost certainly be deploying that.