Elektrine lite

← Feed

@crazyeddie__dup_521@mastodon.social

Post #614958

2026-03-10 15:06 UTC

@thaodan@mastodon.social @fluffykittycat@furry.engineer @merill@infosec.exchange Why? The keys and such associated with the authenticator app should be in a TPM. Something the bootloader can't touch. It can't get the private key to then send it to whoever. The bootloader could attack in other ways and get the info you're accessing once logged in, but I don't think it can mess about or bypass the actual security mechanism. I think they're trying to sell bullshit here so the ignorant support them as they lock us all down.

Replies (3)

  • @thaodan@mastodon.social @fluffykittycat@furry.engineer @merill@infosec.exchange On phones without a TPM that's obviously not the case, but there are fewer and fewer of those and will be fewer still.

    Open ##615010

  • @thaodan@mastodon.social 2026-03-10 16:58

    @crazyeddie@mastodon.social @fluffykittycat@furry.engineer @merill@infosec.exchange The bootloader itself isn't the concern but the kernel and what is started afterwards. It is a factor even if they only use it as an excuse. Most phones don't have a TPM but an ARM trustzone which can run a software TPM. The problem is that modifying or writing isn't possible low level only over the OS or vendor API's provided.

    Open ##615996

  • @crazyeddie @thaodan @merill unlocked bootloaders are a moral imperitive. Not to mention all the ewaste created by locked devices not being repurporsable

    Open ##1207468