Signing TLS handshakes inside a TPM
15 points by bschaatsbergen 9 hours ago | 6 comments

duk3luk3 3 hours ago
Sounds interesting; too bad all we get is text made up by an LLM rather than any of the author's insights.
reply
abound 3 hours ago
Yeah I was interested for the first few paragraphs, then all of a sudden I get hit with two "genuinely"s and a

> That’s the third property, and it’s the one that decides this.

and I gave up at that point.

reply
ram_rattle 2 hours ago
Nothing new here, attested TLS was being discussed in IETF for quiet sometime right?

https://datatracker.ietf.org/doc/draft-fossati-tls-attestati... https://www.youtube.com/watch?v=MF9AwkMJOlw

reply
ranger_danger 2 hours ago
Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking.

It's bad enough that ssh does this by default with all your keys.

reply
altairprime 22 minutes ago
Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay.
reply
ranger_danger 56 seconds ago
Currently yes, but there's not much stopping Chrome etc. from adding a new feature that has a way of presenting a client certificate to a website in a backwards-compatible manner.

Of course the website itself would need to support that, but it's all possible in time.

reply