Post #1498050
2026-01-31 14:36 UTC
@pid_eins @blixtra @brauner @davidstrauss @rodrigo_rata @michaelvogt @pothos @zbyszek @daandemeyer @cyphar @jrocha Sounds interesting. Is the goal based on a threat model? Does "verifiable integrity to Linux systems" mean software and hardware? Or just software?
Replies (1)
-
@zbyszek@fosstodon.org 2026-02-01 08:52
@tor The threat model is any exploit (or bug!) that leads to persistent modification of the software stored on disk. The idea is that after a reboot, you _know_ what software was started (or the attestation fails). The hardware is off-the-shelf standard stuff, only needs a TPM. This is about the integrity of the OS and its payload.