nolaviz ([personal profile] nolaviz) wrote in [personal profile] mjg59 2022-04-07 06:34 am (UTC)

Re: Token Binding/Proof of Possession

Let's make this even better...

Can a local process somehow tell the TPM to shut down until reboot? Then we could also have a local daemon that tracks client state, and if it detects a compromise - it would disable the local TPM, which would cause the already-issued tokens to become useless.

(Sure, an attacker taking over the client could disable this daemon; but it's another hurdle.)


Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org