• 5 Posts
  • 749 Comments
Joined 3 years ago
cake
Cake day: August 11th, 2023

help-circle









  • I try to follow a multi-factor, multi-domain model.

    So if I am wanting to verify that data is on the system I except it to be then TPM keys and measured boot is what I use. To verify it is on the network I expect I use a Tang server. To verify I have possession of a device I use, a hardware token and password.

    You could do all the above, or mix match depending on the system. For example for servers I assume they need to boot without user intervention, so password is set as backup to the Tang server. I still use hardware token to buy just for quick revoktion of verification (i.e. I know a server is compromised or could be soon, I can just pull a USB out).

    The same setup works for my laptops, which makes my network because of Tang act as trusted domain as well.

    So again multi-factor (something you have, know, are, do) and multi-domain (network, user, machine).

    I use Clevis to do the multi-key unlocks.











  • yeah, i cant even agree with the assumption “these new tools have already revolutuonized how we creatr and use software”.

    when it actually turns a fully cycle let me know. There have been at best some edge cases where its worked and some minor workflow alternitives that are take it or leave it. I want it automated too personally. Im fully camp automation. Im tracking all of the latest devolipmemts when i can, but it currently is just not worth the squeeze.