-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Dec 01, 2016 at 04:32:50PM +0100, Swâmi Petaramesh wrote:
> Hi Rusty Bird, and thanks for your help,
> 
> Please see below.
> 
> > 
> > Is the SINIT module working? Run the "find" command from step 2b of
> > /usr/share/doc/anti-evil-maid/README, but look at the lines for PCRs
> > 17, 18, and 19 instead: They should have very random-looking values.
> 
> Uh... Lines 17-19 are all FF
> 
> On my system :
> 
> PCR-00 to 07  look random
> PCR-08 to 12  are all 00
> PCR-13                looks random
> PCR-14 to 16  are all 00
> PCR-17 to 22  are all FF
> PCR-23                are all 00
> 
> So the problem seems to be there... But I don't know what to do with
> this (I know almost nothing about TPM...)

Rusty, Matt rightly just pointed out to Qubes Security Team that the
current behaviour of AEM could be misleading. AEM should refuse to work
if TXT isn't really working - otherwise it's easy to not notice it and
have false sense of security.

- -- 
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYd3nBAAoJENuP0xzK19csxfYH/AngaxY7yDmLXBc8sZufHjg4
lv3nM1otgcQmYxzvIyWDut0qbpLLhmqnQ4StntS/ajesdzFZnKghS0LyJmNjAG/9
hiyfNGYMEml738SCaNujCq2c75ZLi3SFELtPqk4TT4pSJ4rGXX39d2rcnQxs4pGy
xYpkUcWSnLQKQXnkWKphkzAx4IpsaVwtgntVpLYDJ2J0owp4BbtoyBFfDztvEICU
Hp0+r5wUtP8XuuQ6SB3+OqvOeymsgp6SRQln8LsLChQApxk1wC7XiNx3k6rN/nYa
wbo2kI0Plir7SSnYXCNmwyR3S3O45AVxQSMphDHUUw6bC0o+xk3Z6+K6WaAGObk=
=NzFB
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20170112124241.GA17864%40mail-itl.
For more options, visit https://groups.google.com/d/optout.

Reply via email to