Tak jsem konečně upravil šifrování disků na svých počítačích.
Do teď jsem zamykal heslo root file systému do #tpm2 vlastním scriptem popsaným zde:
https://skorpil.cz/en/project/42/mkinitcpio-tpm2-encrypt

To řešení je už 5 let staré a překonané. Ale stále funkční. Dneska už to umí #systemd nativně. Porušil jsem pravidlo "nešťourej do něčeho co funguje" a přenastavil jsem šifrování na všech počítačích. Dneska je to fakt super pohodlné nastavení.

Nechcete nějakou minipřednášku o šifrování disků pomocí TPM2 na #LinuxDays ? Zaměřeno na #Arch, jiné distribuce tolik vyzkoušené nemám. Ona jedna přednáška byla už na tom loňském, tak nevím jestli je to potřeba. 🤷

Mkinitcpio tpm2 encrypt

All my personal and company computers are powered by Arch Linux with encrypted storages. This setup brings an inconvenience of entering two passwords on startup. One unlocks the storage encryption, second logs me to my user account. Isn't there a way to unlock the system volume automatically? Mobile phones for example also encrypt their storages and still we don't have to enter a password during boot.

Štěpán Škorpil
DICE und EA haben die offiziellen #Hardware-#Anforderungen für #Battlefield6 veröffentlicht. Mindestens eine RTX 2060 und 16 GB RAM werden benötigt. Interessant: #TPM2.0 ist Pflicht, eine #SSD hingegen nicht. https://winfuture.de/news,153266.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
Battlefield 6: das sind die offiziellen Hardware-Anforderungen

EA und DICE haben jetzt die offiziellen Hardware-Anforderungen für das kommende Action-Spiel Battlefield 6 veröffentlicht. TPM 2.0 und Secure Boot müssen demnach verfügbar und aktiviert sein, das Spiel setzt aber keine SSD voraus.

WinFuture.de
Ein neuer Alternate-PC hat Einzug gehalten. Um mit #TPM2 #LUKS verschlüsselte Festplatten automatisch zu entschlüsseln, ohne Passwort-Anfrage mit einer noch besseren Grafikkarte dabei. Die vom Debian Paketsystem noch nicht unterstützt wird.
Lernkurve: Secure Boot, Nvidia Open Modules kompilieren und signieren um die GrKa auszureizen. Dann wie man das automatische Entschlüsseln durchführt und wie das Gerät in /etc/fstab angegeben wird.
3,5 Tage neuer Spaß. Schön.
Erfolg!
 
Worried about rogue devices compromising your encrypted #Linux system? Discover how #openSUSE combines #TPM2, #FIDO2, and measured boot to fortify #FDE installation. https://news.opensuse.org/2025/07/18/fde-rogue-devices/
Protecting against rogue devices in openSUSE with Full Disk Encryption

openSUSE have now multiple ways to configure a Full Disk Encryption (FDE) installation. A very secure and easy way (YaST2) of doing this is via user space to...

openSUSE News
Boot-time trust, #TPM2 sealing, and stopping fake rootfs attacks; #openSUSE’s new Full Disk Encryption defenses are wild. Read the #tech deep-dive. #infosec #openSUSE #TPM2, #PCR #FDE #sysadmins #security #opensource https://news.opensuse.org/2025/07/18/fde-rogue-devices/
Protecting against rogue devices in openSUSE with Full Disk Encryption

openSUSE have now multiple ways to configure a Full Disk Encryption (FDE) installation. A very secure and easy way (YaST2) of doing this is via user space to...

openSUSE News

How to Enable TPM 2.0 on Windows 11

Upgrade to Windows 11 without errors! ✅ Learn how to check, enable, and verify TPM 2.0 in BIOS/UEFI, activate Secure Boot, and prepare your PC for a smooth, secure installation today.

#Izoate #technology #howto #windows #Windows11 #TPM2

https://www.izoate.com/blog/how-to-enable-tpm-2-0-windows-11-step-by-step-guide-to-turn-on-tpm-2-0-and-secure-your-pc-for-windows-11-upgrade/

How to Enable TPM 2.0 Windows 11: Step-by-Step Guide to Turn On TPM 2.0 and Secure Your PC for Windows 11 Upgrade - Izoate

Are you looking to enable TPM 2.0 Windows 11? Learn how to turn on TPM 2.0, check your PC’s TPM status, configure Intel PTT or AMD fTPM in BIOS/UEFI, and meet Windows 11 upgrade requirements quickly and safely.

Izoate
GitHub - puavo-org/tpm2_library

Contribute to puavo-org/tpm2_library development by creating an account on GitHub.

GitHub

Call of Duty: Black Ops 7 PC’de oynamak isteyenlerin TPM 2.0 ve Secure Boot’u etkinleştirmesi gerekecek. Detaylar haberimizde.
#CallofDuty #BlackOps7 #Güvenlik #TPM2 #SecureBoot

https://www.teknoblog.com/call-of-duty-black-ops-7-guvenlik-sartlari-aciklandi/?utm_source=mastodon&utm_medium=jetpack_social

Call of Duty: Black Ops 7 güvenlik şartları açıklandı

Call of Duty: Black Ops 7, PC’de TPM 2.0 ve Secure Boot etkin olmadan çalışmayacak. Activision yeni gereksinimleri önceden duyurdu.

Teknoblog
How secure is your Full Disk Encryption? #openSUSE digs deep into mitigating rogue device attacks using #TPM2, #PCR extensions, and custom #initrd validation. A must-read #FDE for #sysadmins & #security pros. #opensource https://news.opensuse.org/2025/07/18/fde-rogue-devices/
Protecting against rogue devices in openSUSE with Full Disk Encryption

openSUSE have now multiple ways to configure a Full Disk Encryption (FDE) installation. A very secure and easy way (YaST2) of doing this is via user space to...

openSUSE News
Ubuntu 25.10 Adds Optional TPM 2.0, Echoing Windows 11 Security Moves, Raises User Concerns.

The tech world often watches Windows for big moves, and when Windows 11 dropped, it brought a surprising new rule. To get the latest Microsoft system, your

Blaze Trends