Quantcast
Channel: Raspberry Pi Forums
Viewing all articles
Browse latest Browse all 4829

Advanced users • Re: How to use OTP as a key provider for LUKS automount?

$
0
0
But that is exactly the script I see as a problem: grab it off the github, add to unencrypted root partition with some pointer to execute it and you successfuly read keys needed for decryption.
thats why you need to combine it with secure-boot, so only a correctly signed /boot partition can boot
then unauthorized changes like that just never run
for the pi5, the comments claim it goes into a proper secure key store, but i havent been able to verify anything on how secure it is
The script says "IMPORTANT: Raspberry Pi 5 and earlier revisions do not have a hardware secure key store." though?
on re-reading that, yeah, its basically saying every model lacks a secure key store
so why did they even bother mentioning the 5??
why mention secure key store at all??

Statistics: Posted by cleverca22 — Thu May 23, 2024 10:53 pm



Viewing all articles
Browse latest Browse all 4829

Trending Articles