Skip Navigation
Jump
Is anyone here using their hardware TPM chips for credentials?
  • A security module or a key fob/smart card processes the key internally using its own dedicated ram and cpu without any debugging support. This way, even something will full ram and cpu access or a compromise of your machine, there is no way to export or access the key. Data is passed to the module and it returns the scrambled or unscrambled result based on the key which no body knows or has ever seen. A key locked with no way to access can’t be hacked without physically stealing the module, which is where your pin comes in to save you. The TPM is a very important part of a secure boot chain. If you want to secure other things I wouldn’t blame you for using a separate module or fob that isn’t always connected util it’s actually needed and it should only be activated with a physical button or something so you have to be present to engage with it. This adds even more security. So you could use the TPM for boot chain security and a separate fob or data privacy for example.

    2
  • Jump
    Commercial Flights Are Experiencing 'Unthinkable' GPS Attacks and Nobody Knows What to Do
  • What about GLONASS, Galilleo, or BDS? Are they all being equally jammed? Why wouldn’t they sync with all of them and use a consensus to determine accuracy? Like having multiple ntp servers.

    22
  • Jump
    Google Chrome's new "IP Protection" will hide users' IP addresses
  • They stopped caring about your ip address and have moved to profiling, so they’ll gladly help you change your ip address to get more from you.

    3
  • Jump
    Looking for phone system over LAN (but not PBX, if I can help it).
  • You could configure the sip phones to point directly to one another. No pbx needed. Just “call” and ip address. You only need the pbx to translate/authenticate/provide features. Sip invite comes into phone, making phone ring, pickup phone, and rtp goes directly to phone just like the sip invite. so long as there are no translations causing issues in between, so it actually works best on a private direct network between them.

    2
  • Jump
    Chrome Root Store policy update looking to require an automated option for obtaining certificates
  • Google trough the Chrome Project are pushing certificate authorities to offer automated certificates services to customers to make their use more prolific. Certificate authorities only have value if they are included in the certificate store, so they will do whatever it takes to be in there. Certificate authorities are the organizations we trust to say if a website is secure enough to display the lock in the browser instead of an error.

    6
  • Jump
    Rudy Giuliani expected to surrender in Georgia election interference case: Sources
  • And he’ll certainly have all his bail prearranged so he will show up and go home afterwards. I don’t see why they act like these people are actually being arrested or will actually even see bars.

    1