Post B6v2LgDb29sJVRFCBE by privateger@plasmatrap.com
(DIR) More posts by privateger@plasmatrap.com
(DIR) Post #B6v1g3ajk5nfpnDjPs by privateger@plasmatrap.com
0 likes, 0 repeats
i do kind of wonder why there's been no real strides in moving cookies into TPM boxes somehowhaving them in a file still seems... very limited
(DIR) Post #B6v1k3KgeAJqBpcPpY by privateger@plasmatrap.com
0 likes, 0 repeats
I will pre-move hereHardware security is good, actually, and not equal to remote attestation
(DIR) Post #B6v278U3f35epI0bbs by cat8124@mk.ilyamikcoder.com
0 likes, 0 repeats
@privateger@plasmatrap.com because there's no infrastructure for storing arbitrary data in tpm?
(DIR) Post #B6v278fOysAFOTJfI8 by privateger@plasmatrap.com
0 likes, 0 repeats
@cat8124@mk.ilyamikcoder.com yes, but there is for key management, which one could use here
(DIR) Post #B6v2CWIwWWek9XNRei by privateger@plasmatrap.com
0 likes, 0 repeats
@cat8124@mk.ilyamikcoder.com the proper solution would be a move to token binding, meaning that the session would be bound to a private key that lives in the TPM and logins would be a HSM signature of a challenge
(DIR) Post #B6v2LgDb29sJVRFCBE by privateger@plasmatrap.com
0 likes, 0 repeats
@cat8124@mk.ilyamikcoder.com apparently I cannot use a search engine, because I just re-invented exactly what DBSCs arehttps://developer.chrome.com/docs/web-platform/device-bound-session-credentials