home.social

#tpm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tpm, aggregated by home.social.

fetched live
  1. Lara Greaves also discusses NatACT First's response to TPM's electorate-only campaign;

    feeds.95bfm.com/link/18452/174

    Claiming that TPM are gaming the system to tip the outcome of the election. Which is pretty fucking rich, given all the antidemocratic voter suppression policies NatACT First have pushed through to keep themselves in government, whether that's what the majority of voters actually want.

    Arguably TPM's strategy just levels the playing field a bit.

    (1/2)

    #TPM #NZElection2026

  2. #TPM vulnerabile su milioni di CPU AMD: perché il BIOS va aggiornato
    go.squidapp.co/n/ILhGxfV

  3. Das #TPM in vielen #AMD- und #Intel-Prozessoren ist unsicher. Zwei schwere Sicherheitslücken ermöglichen Manipulationen am System erfordern aber lokalen Zugriff mit Rechten. Firmware-Updates sind bereits im Umlauf, auch Software-Patches für Betriebssysteme werden verteilt. heise.de/news/Der-Security-Ko-

  4. #AMD confirms #Ryzen #TPM vulnerabilities, #ASUS, #MSI and #GIGABYTE already have fixes videocardz.com/newz/amd-confir

    «AMD’s mitigation table shows that most desktop fixes were actually completed in May. Ryzen 3000 received #ComboAM4PI 1.0.0.11 on May 18, while Ryzen 4000 and Ryzen 5000 use #ComboAM4v2PI 1.2.0.12 released to OEMs on May 27»

    MSI sacó la actualización para el modelo de placa base que tengo el 22 de julio.

  5. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  6. Thin Client? Thin Crypto: An overview. ― Darren McDonald | AmberWolf

    blog.amberwolf.com/blog/2026/a

    "… Back in February 2025 I found a simple bug, a thin client operating system that saved its crash dumps to the disk unencrypted. Shocked by what I saw, I started looking deeper and found a very suspicious looking Key Derivation Function (KDF) protecting the disk encryption. I pulled on that thread for 18 months, and ended up finding a pile of bugs big enough that it got me a speaking slot at DEF CON 34 main track. This blog post is an overview of what happened, and where it leaves thin client full disk encryption in general.

    The short version of what I discovered is that every one of the three vendors that dominate the thin-client market, HP, Dell and IGEL, shipped full disk encryption you can defeat. As of early 2026 that was true across all three at once. The complexity of these attacks was fairly low, not at all what the phrase “TPM attack” usually conjures. No bus-sniffing, no glitching, no cryptanalysis. It was mostly reading bash scripts and using a USB stick. …"

    #FreeBSD #GELI #HP #Dell #TPM #IGEL #PCR #KDF

  7. CW: Linux-Kram, Installation LMDE

    Gerade ein #Linux #Mint (Debian Edition) auf dem #HP #ZBook (von 2016) vom Kollegen installiert. Laptop in der Firma aussortiert.

    Hat aber erst im 3. Anlauf funktioniert und dann auch nur ohne Verschlüsselung!

    Ich habe den Verschlüsselungschip (TPM?) im Verdacht. Die Installation mit Verschlüsselung blieb immer irgendwo hängen und das System kam nach Abbruch und Neubooten vom Ventoy-Stick nur im abgesicherten Modus hoch. Kein Weiterkommen.

    Beim Booten gibt es (auch jetzt noch) entsprechende Errors.

    Lässt sich dieser #TPM-Chip irgendwie abschalten? - Verschlüsselung wäre schon gut bei ‘nem Laptop.

  8. Desaceleración económica generó que el Banco Central redujera la Tasa de Política Monetaria al 3%

    Incidió también la elevada incertidumbre externa, asociada a los conflictos geopolíticos, la evolución de los precios internacionales de las materias primas y los posibles efectos de condiciones climáticas extremas sobre la producción.
    La entrada Desaceleración económica generó que el Banco Central redujera la Tasa de Política Monetaria al 3% aparece primero en Semanario Universidad.

    #BancoCentral #Economía #País #Préstamos #TASADEPOLÍTICAMONETARIA #TPM #ÚltimaHora

    semanariouniversidad.com/pais/

  9. Microsoft führt die TPM-Pflicht nun auch bei Windows Server ein. Zukünftige KMS-Hosts müssen ihre Hardware per Chip nachweisen, um Lizenzen zu verteilen. #WindowsServer #TPM winfuture.de/news,160164.html?

  10. Заметки Note: P2P-синхронизация, локальное шифрование и режим «под принуждением»

    По-настоящему важные данные нельзя держать в одном единственном месте — их нужно диверсифицировать. Можно хранить всё дома и однажды вернуться с прогулки, а вместо дома и драгоценного компьютера — одни обугленные руины. Можно носить всё с собой в телефоне, но лишиться его в первом же кафе, где аппарат вытащит у вас из кармана воришка. Можно загрузить всё на надёжный сервер крупной корпорации, но в один прекрасный день эта корпорация введёт против вас санкции или просто заблокирует доступ к вашему же аккаунту. У каждого отдельного хранилища есть свой собственный способ вас подвести. Вот ровно эту проблему я и попытался решить.

    habr.com/ru/articles/1060536/

    #заметки #синхронизация #шифрование #peertopeer #криптография #информационная_безопасность #TPM #Android_Keystore #open_source #кроссплатформенность

  11. Créditos de consumo siguen sin bajar lo suficiente y de tarjetas más bien subieron

    Pese a que el Banco Central redujo en 0,75 puntos porcentuales la Tasa de Política Monetaria en el último año, los bancos colocan cada menos préstamos según investigación de la OES-UNA.
    La entrada Créditos de consumo siguen sin bajar lo suficiente y de tarjetas más bien subieron aparece primero en Sema [...]

    #BancoCentral #Consumo #Créditos #País #TASADEPOLÍTICAMONETARIA #TPM #ÚltimaHora

    semanariouniversidad.com/pais/

  12. Nie musisz dopłacać za spokój

    Czy to normalne, że czytnik linii papilarnych znika z podstawowych konfiguracji urządzenia i jest sztucznie zarezerwowany tylko dla droższych modeli laptopa? Analizujemy rynkowe absurdy i pokazujemy, jak architektura Secured-core PC, układy TPM 2.0 oraz wbudowane funkcje Windows 11 Pro chronią dane małej firmy bez ukrytych dopłat.

    Wymogi dyrektywy NIS2 oraz unijnego rozporządzenia RODO nie zawierają klauzul wyłączających dla sektora małych i średnich przedsiębiorstw ani dla środowisk Small Office-Home Office. Niezależnie od wielkości zasobów sprzętowych, pełna odpowiedzialność karna i finansowa za ochronę przetwarzanych informacji spoczywa na podmiocie gospodarczym. W tym kontekście obserwujemy na rynku elektroniki użytkowej wysoce ryzykowny trend projektowy. Część producentów sprzętu zaczęła traktować elementarne funkcje kryptograficzne i autoryzacyjne jako opcjonalne wyposażenie, podlegające rynkowej segmentacji. Bezpieczeństwo punktów końcowych, zamiast stanowić fundament urządzenia, staje się funkcją dostępną po dopłacie w sklepowym konfiguratorze. Z perspektywy fundamentów bezpieczeństwa IT jest to podejście błędne, ponieważ łańcuch zabezpieczeń infrastruktury w każdej firmie jest dokładnie tak silny, jak jego najsłabszy punkt końcowy.
    Przykładem tego zjawiska jest strategia przyjęta przy niedawnej premierze budżetowego MacBooka Neo, pozycjonowanego jako nowy punkt wejścia do ekosystemu Apple. Wersja bazowa tego komputera, wyceniona na ok. 3 tys. zł, została pozbawiona czytnika linii papilarnych Touch ID. Sprzętowa autoryzacja biometryczna została zarezerwowana wyłącznie dla modeli wyposażonych w dysk o pojemności 512 GB i większym, wymagających dopłaty.
    W urządzeniach Copilot+ PC opartych na systemie Windows 11 Pro architektura bezpieczeństwa jest bardziej spójna. [...]

    #ARTYKUŁSPONSOROWANY #Microsoft #Pluton #TPM #Windows

    niebezpiecznik.pl/post/nie-mus

  13. "WEI wasn't an effort to level the playing field between apps and the web – it was a race to the bottom, an attempt to make the web as enshittogenic as the app hellscape.

    Public outrage to WEI killed the project, but Google's commitment to augmenting its illegal commercial lockdown efforts with technical lockdowns never ended. Now, Google has rolled out an experimental "reCAPTCHA Mobile Verification" that uses an app, your camera, and your device's TPM or secure enclave to produce an attestation about your Android device:
    (...)
    This will make it much easier for the apps and other services you interact with to block your device if you run an Android alternative, or if you install a mod that overrides the actions of Google's stock Android:
    (...)
    This is a terrible idea – it's every bit as bad as WEI was. In an age in which Big Tech is ever-more tied to authoritarian governments, redesigning our devices to tell strangers things we don't want them to know isn't just shortsighted, it's inexcusable."

    pluralistic.net/2026/06/12/com

    #Google #Surveillance #Android #Privacy #reCAPTCHA #TPM

  14. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  15. > Reforms that would break the supermajority right-wing Court’s grip on the country — its operating as a legislative veto for Democratic administrations and a hall pass for Republican ones — would go far beyond docket management and ethics reforms, though. Term limits, court packing, jurisdiction stripping — the ideas lighting up the intellectual left and spreading to Democratic officials would overhaul the Court as we know it. 

    talkingpointsmemo.com/news/dem

    #scotusreform #uspol
    #democrats #republicans
    #constitutionalreform
    #talkingpointsmemo #TPM
    #jamieraskin #kamalaharris
    #RubenGallego #darrellissa
    #michaelbaumgartner
    #callaisdecision #votingrights
    #mitchmcconnell #abrahamlincoln

  16. "Trusted Platform Module (TPM)" lügt doch schon beim Namen - wie soll ich etwas vertrauen, was propritär ist und keinerlei Einsichtnahme in die Funktionsweise erlaubt?

    Ich finde "Untrusted Platform Module (UPM)" oder "Please believe me I am a good Module (PBMIAGM)" wäre besser.

    #TPM

  17. Did a new release of ssh-tpm-agent.

    github.com/Foxboron/ssh-tpm-ag

    `ssh-tpm-add` now supports `-c` for confirmation dialogs before key usage, along with a nice process chain. Thanks to @mic92

    #TPM #Security #OpenSSH #SSH