I picked up a shitty NUC from ewaste and it had a label on it for an AI company
digipres.club
digipres.club
Also, worth noting that they are currently in need of some help, so consider supporting them: https://digipres.club/@foone/112929955279707608
Using that you could set up networking and download the key from somewhere (say a remote KMS that would need user approval before continuing). So you would reduce your problem to being prompted on phone to unlock your desktop.
You could even use some sort of hardware key to prove request came from the physical server. (simplest might be a RP2350 with some key burnt in)
Or you could use something like SGX if it's still available anywhere to prove the same.
...unless your distro uses systemd, which removes keyscript support [1] because the systemd guy "really dislikes generic callouts"
Did not hear about booster. Its README claims "Clevis style data binding. The encrypted filesystem can be bound to TPM2 chip or to a network service.". Does it mean that it tries to deliver various bindings independently from clevis pins, even when duplicating their functions?
I do this with a gateway/router on a PC Engines APU2 that has an internal SSD.
Just ensure GRUB includes the requisite USB modules in its core image, or use grub-mkstandalone to include all modules in core.
With LUKSv2 the seven slot limit doesn't apply.
For headless GRUB is configured to the serial port for its terminal in/out so a passphrase can be typed.
If hardware is stolen it will have hardware key attached.
It is similar to having unencrypted ssd.
Also, someone can temporarily remove the yubikey, fetch the decryption key then place it back.
Key is on my keychain. not attached to the box. I don't need to unlock it remotely. I want to be there and plug my key and touch it and yank it.
> Also, someone can temporarily remove the yubikey, fetch the decryption key then place it back.
If implemented correctly. Nobody can. An encrypted LUKS key would be sent to the yubikey and have it decrypted there. Not the other way.
Disclosure: I am a co-author of Mandos.
[1] "data processor" in the sense of the various user data protection laws, not just any data processor
>view it as red flag and throw his resume away
>dude is Linus Torvalds
It's a phase we all go through, but some of us are stuck there forever.
The answer to this type of thing is full disk encryption (FDE). There’s zero reason not to have it on every device at the block level. Especially if you’re going to be processing highly sensitive data.
You can’t even trust disks to actually delete things anyway. So the only way to be sure that information is not leaked is to prevent it from ever being persisted to disk in plaintext.
Stage 2: "For consistency, we'll handle our second and third secrets just like that first secret. Or handle them through our existing configuration management system, with just some minor tweaks."
Stage 3: "If we mess up the credentials for these edge devices, the software update, monitoring and remote management features will break and we'll have to recall the devices. We should be very cautious about making any changes."
Stage 4: "Even with a secret manager, we'd have to protect the credential used to access the secret manager. Not to mention a long-lived credential to bootstrap new devices, or re-image broken devices in the field. The real solution here is Secure Boot and credentials tied into the TPM. If we want to do this, we'll need a team of six full-time developers and our own custom linux distro"
Stage 5: "End-user features and business value are our priority right now, credential rotation is on the schedule for Q3 next year"
This hash of 24 chars is my password for that account. I don't trust any of the online password managers. Is this actually safe or not?
Note: this is not used for any of my professional work
Alternative approach, hang out outside your target location to figure out when/where they throw stuff, and when trash collectors come. Arrive somewhere in between and dumpster dive :)
How often that is taken into consideration is another matter.
Instead this console just has to get destroyed. And for what? It’s not even like a Nintendo 64 is going to have any personal data on it that poses any danger to the previous owner.
And on the flip side if the argument is that the electronics could be dangerous because they are broken. I probably run the same risk when buying electronics second hand anyway. So I don’t think that should prevent them from letting people pick up things either.
Yeah, most definitely, which is why you need to befriend them before asking, otherwise it's a guaranteed "No, we cannot do that".
On paper, that’s a catastrophe. In practice, however, even criminals won’t extract much value from these random logs and video records.
- getting private numbers of known people (from "call Some Name")
- spam targeting from calendar event creation
- various private info available from dictated notes
It would still be my problem at the end of the day.
Also, serious cloud providers (besides using server-grade hardware) have to follow proper equipment destruction and recycling procedures--Azure datacenters, for instance, used to have an on-site industrial shredder for disks (which were nevertheless hardware encrypted, but any failing storage was destroyed anyway).
In this case, there’s no indication of that and it’s so poorly handled that it radiates a startup winging it where they “didn’t have time” to hire anyone with a clue since the AI gold rush was right there. Given the reported healthcare data this seems like an especially bad choice.
I heard NUC now goes to ASUS, perhaps the devices can improve. There are quite a few problems here.
I mean I expected abysmal performance on any pure CPU AI task, but some of those could have run in the background. I wonder what Intel did with the time they were the dominant player on a lot of markets...
The security here is just that the device is so bad, that no party could extract something useful. Seriously, these things...
Picked up a SFF Dell desktop from a huge pile of identical ones in a large cardboard box last spring. They had the good sense, however, to harvest the SSD and memory. Got replacements for a song and now I run home assistant on that thing.
There's also sometimes "old iron" in the dock. Sun servers from back in the day. Beautiful hardware but not something one would ever want to take home.