home.social

#measuredboot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #measuredboot, aggregated by home.social.

  1. @Gentoo_eV Given that I get a KVM console in time, I will demonstrate my installation guide (gentoo.duxsco.de/) in English using a #Hetzner dedicated server.

    • What? Beyond Secure Boot – Measured Boot on Gentoo Linux?
    • When? Saturday, 2024-10-19 at 18:00 UTC (20:00 CEST)
    • Where? Video call via BigBlueButton: bbb.gentoo-ev.org/

    The final setup will feature:

    • #SecureBoot: All EFI binaries and unified kernel images are signed.
    • #MeasuredBoot: #clevis and #tang will be used to check the system for manipulations via #TPM 2.0 PCRs and for remote LUKS unlock (you don't need tty).
    • Fully encrypted: Except for ESPs, all partitions are #LUKS encrypted.
    • #RAID: Except for ESPs, #btrfs and #mdadm based #RAID are used for all partitions.
    • Rescue System: A customised #SystemRescue (system-rescue.org/) supports SSH logins and provides a convenient chroot.sh script.
    • Hardened #Gentoo #Linux for a highly secure, high stability production environment.
    • If enough time is left at the end, #SELinux which provides Mandatory Access Control using type enforcement and role-based access control
  2. Auditor app version 78 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/9761-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  3. Auditor app version 77 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/8830-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  4. Auditor app version 76 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/8065-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  5. Auditor app version 75 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/7900-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  6. Auditor app version 74 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/6368-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  7. Auditor app version 73 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5834-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  8. Auditor app version 72 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5715-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  9. Auditor app version 71 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5420-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  10. Auditor app version 70 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/4972-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  11. We currently sign our factory images releases with the signify tool from OpenBSD. It provides tiny signatures that are easy to verify on any distribution with signify in their repositories. This is much less important than in the past because you can verify the completed install.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor #signify #openssh

  12. Auditor app version 69 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/4597-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  13. Auditor app version 68 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/3216-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement