Signing TLS handshakes inside a TPM
15 points by bschaatsbergen 9 hours ago | 6 comments
ram_rattle 2 hours ago
Nothing new here, attested TLS was being discussed in IETF for quiet sometime right?
replyhttps://datatracker.ietf.org/doc/draft-fossati-tls-attestati... https://www.youtube.com/watch?v=MF9AwkMJOlw
ranger_danger 2 hours ago
Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking.
replyIt's bad enough that ssh does this by default with all your keys.
altairprime 22 minutes ago
Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay.
replyranger_danger 56 seconds ago
Currently yes, but there's not much stopping Chrome etc. from adding a new feature that has a way of presenting a client certificate to a website in a backwards-compatible manner.
replyOf course the website itself would need to support that, but it's all possible in time.
> That’s the third property, and it’s the one that decides this.
and I gave up at that point.