• 1 Post
  • 29 Comments
Joined 1 year ago
cake
Cake day: September 8th, 2023

help-circle










  • Yes. That is possible. However if the hardware configuration/software configuration changes the TPM should trip and prevent decryption.

    The attackers would have to break you ssh/terminal/lock screen/other insecure software. However code injection should be impossible because you used custom secure boot keys and ideally a signed unified kernel image. (Can’t even change kernel params without tripping TPM.)

    You would not be safe if they did a bus listening attack or if your shell pwd is not safe. If that is your threat vector this may not be a good option for you.