HP ThinPro’s TPM-sealed LUKS key falls to a tweak in the unencrypted boot partition, since PCRs miss initramfs and kernel.
trending4
01 02 DEF CON 34 repo with slides and PoCs for bypassing thin-client FDE via boot/firmware bugs, not by cracking the crypto.03 Ubuntu’s virtualization hardware enablement (HWE) stack: a new model for confidential computing enablement ubuntu.comUbuntu outlines a rolling HWE stack for virtualization, extending LTS support to QEMU, libvirt, and firmware for SEV-SNP and TDX, because...04 Need PQC in a firmware TPM, or just smaller builds and stricter locality handling? wolfTPM v4.1.0 tries both.