keylime
mortar
Our great sponsors
keylime | mortar | |
---|---|---|
2 | 17 | |
375 | 208 | |
1.3% | - | |
9.0 | 5.9 | |
8 days ago | 5 months ago | |
Python | Shell | |
Apache License 2.0 | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
keylime
-
The Danger of Microsoft Pluton
It is still under development, but try Keylime[1]. They have also a nice agent written in Rust[2] with low footprint.
I write some notes[3] about how to use it in openSUSE MicroOS / Tumbleweed, but can be extrapolated to many other distributions too.
[1] https://github.com/keylime/keylime
-
Will Proxmox be able to run Windows 11?
It looks like qemu 6.0 has tpm 2.0 as a milestone feature: https://github.com/keylime/keylime/issues/29
mortar
-
WTF is a KDF? A startling revelation from a French prison
Bruteforce of such random password is just not plausible and talks about KDF "weakness" is just a distraction. I think most likely it was evil maid attack.
Here are projects which try to mitigate some of evil maid attack risks:
https://github.com/noahbliss/mortar
https://safeboot.dev/
-
Installation with full-disk, two-factor encryption, secure boot, and TPM
Secure boot and TPM support (à la Mortar: https://github.com/noahbliss/mortar)
-
Complying with the future: Secure Boot and TPM unclocking
There are tools that look to be able to automate it: https://github.com/noahbliss/mortar/blob/master/docs/proxmox-install.md
-
Prevent backup of vTPM2.0 state?
I just went through the process of setting up new ubuntu VM's using full root disk LUKS encryption and auto-unlock via Proxmox's vTPM2.0 and UEFI ( via this extremely helpful resource https://github.com/noahbliss/mortar )
-
tpm2 + luks + ubuntu 18 setup?
I have used this project with Debian+proxmox and it's been working great. https://github.com/noahbliss/mortar but I did read the arch wiki a bit which helped my understanding.
-
What do you don't like about Linux? What is Windows doing better?
There's a project called "mortar" (as in, gluing all these bricks together) that was attempting to simplify this. Though it's lost steam, reading through it's simple bash scripts was a great place to start for me. This guide for Fedora also helped a lot.
-
Authenticated Boot and Disk Encryption on Linux
There have been a number of attempts to solve this problem, but the most complete appear to be Mortar (a project I head) and safeboot.dev
I highly recommend taking a look at either of these projects if you want be able to improve both your convenience through auto unlocking, and security through broadened scope of audit.
https://github.com/noahbliss/mortar
https://safeboot.dev
-
Best Evil Maid prototcol for Linux?
Check out mortar. It uses secure boot and TPM along with LUKS. The creator is super helpful and available on the telegram.
-
Mount encrypted volume at boot?
A more advanced approach would be something like mortar to chain-load signed stuff.
-
Will Proxmox be able to run Windows 11?
There seems to be a workable solution out there for 2.0: https://github.com/noahbliss/mortar/blob/master/docs/proxmox-install.md
What are some alternatives?
confidential-computing-zoo - Confidential Computing Zoo provides confidential computing solutions based on Intel SGX, TDX, HEXL, etc. technologies.
sbctl - :computer: :lock: :key: Secure Boot key manager
swtpm - Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface.
xcp - Entry point for issues and wiki. Also contains some scripts and sources.
clevis - Automated Encryption Framework
cloud-lusat - Cloud Internal Threat Intelligence Feeds, Inventory and Compliance Data Collection
linux-secureboot-kit - Tool for complete hardening of Linux boot chain with UEFI Secure Boot
repo
solo1 - Solo 1 firmware in C
28c3-doctorow - Transcription of Cory Doctorow's keynote from 28C3.
qubes-antievilmaid - Qubes component: antievilmaid