Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Don’t you just hit ESC during boot and change the Linux command line to init=/bin/sh?
 help



TPM will not unseal the key if you change kernel parameters. It's one of the PCRs.

You'll be dropped into "enter disk crypt password please" prompt.


Looks like you can either password protect grub or have the kernel start command part of the list of things the TPM checks before unlocking the key.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: