[52414] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: TPM & disk crypto

daemon@ATHENA.MIT.EDU (Erik Tews)
Fri Oct 13 13:24:30 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: Erik Tews <erik@debian.franken.de>
To: Ivan =?UTF-8?Q?Krsti=C4=87?= <krstic@solarsail.hcs.harvard.edu>
Cc: "Kuehn, Ulrich" <Ulrich.Kuehn@telekom.de>, jamesd@echeque.com,
	cryptography@metzdowd.com
In-Reply-To: <452E89E6.9050000@solarsail.hcs.harvard.edu>
Date: Fri, 13 Oct 2006 15:19:45 +0200


--=-DWKPfWVY8P0UefTsAWKA
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Am Donnerstag, den 12.10.2006, 14:31 -0400 schrieb Ivan Krsti=C4=87:
> Kuehn, Ulrich wrote:
> > Who is "we"? In the case of my own system I payed for (so speaking
> > for myself) I would like to have such a mechanism to have the system
> > prove to me before login that it is not tampered with. The TCG
> > approach does not provide this.=20
>=20
> What does "prove" mean here? Does having a hash of the system state for
> visual inspection before boot do it?

The problem is, just displaying anything like a hash value won't help.
You will need a second device to do a RPA. This device could be a much
smaller one, at least in theory, something like a mobile phone or an pda
would be sufficient.

--=-DWKPfWVY8P0UefTsAWKA
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: Dies ist ein digital signierter Nachrichtenteil

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQBFL5Jx1V7s4RB7CAcRAqH5AJ42HF+ACo8YlOybE+R+vmqHMoTtGgCeNYra
vXlAOeQ7DBsnGjlN+kIMVBY=
=R0bc
-----END PGP SIGNATURE-----

--=-DWKPfWVY8P0UefTsAWKA--


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post