• 7 Posts
  • 688 Comments
Joined 3 years ago
cake
Cake day: August 11th, 2023

help-circle









  • I try to follow a multi-factor, multi-domain model.

    So if I am wanting to verify that data is on the system I except it to be then TPM keys and measured boot is what I use. To verify it is on the network I expect I use a Tang server. To verify I have possession of a device I use, a hardware token and password.

    You could do all the above, or mix match depending on the system. For example for servers I assume they need to boot without user intervention, so password is set as backup to the Tang server. I still use hardware token to buy just for quick revoktion of verification (i.e. I know a server is compromised or could be soon, I can just pull a USB out).

    The same setup works for my laptops, which makes my network because of Tang act as trusted domain as well.

    So again multi-factor (something you have, know, are, do) and multi-domain (network, user, machine).

    I use Clevis to do the multi-key unlocks.


  • Creating stability for ourselves and loved ones really can be demanding and force us into positions that make impossible to be as ethical as we’d want to be.

    That said it is crazy how many people in the “first world” view themselves in that category while the demands they have are “a room and bathroom per person in the household”, keeping the house 69 during the summer and 72 during the winter, a new 1000 dollar phone a year or two, a game system or two total a few k, a newer car because they’re last one is just over 80k miles, several subscriptions to constant instant entertainment, etc.

    Like yes, there really are people that have to beg for more hours to keep a two bed room for themselves and their kids, those people don’t really have a choice. They are also the rest of us that really can just have a little less “treats” and be perfectly fine.