3 ms·
His design is perhaps not 'good' if you were to implement it with the explanation as-is, but his description is hardly an implementation guide. The concept as
by oneplane 2y ago
His design is perhaps not 'good' if you were to implement it with the explanation as-is, but his description is hardly an implementation guide.
The concept as described is used worldwide (by macOS and iOS) and works very well. In contrast to things like BitLocker, OPAL TCG and SED where it's such an "everything is optional"-free for all, there is no real way to be sure.
In the FOSS world, most of this can also be done (combination of self-enrolled secure boot and dm-verity for a heads loader and them LUKS for a OS-stage loader), but the issue is that you can subvert the root of trust and get infinite tries to attack the encrypted data, including when a TPM or SED is involved.