Tag
This hands-on deep dive explains NvPCRs in systemd v262, which are additional PCR-like registers in TPM's NV memory to address PCRs scarcity for security features like disk encryption and remote attestation, with a focus on the reworked secure design.
Chrome begins rolling out Device Bound Session Credentials (DBSCs), a new protection that binds session cookies to a device's TPM or Secure Enclave, making stolen cookies useless for account takeovers.
The article explains remote attestation using TPM to cryptographically verify the state of hosts, ensuring trusted boot and preventing compromised hardware from accessing networks. It covers the benefits and complexities of implementing measured boot and how it can be combined with encryption and mTLS for strong security guarantees.