• 0 Posts
  • 5 Comments
Joined 1Y ago
cake
Cake day: Jul 01, 2023

help-circle
rss

deleting someone’s entire git history

Based on the image text this is for new accounts only. My account has neither phone nor credit card and I’ve not been asked to re-verify. Maybe they’re having problems with bots at the moment.


And no decryption keys for other attached drives.


It’s entirely possible that the translation layer will alter timing to expose a race condition such that something doesn’t render.


Isn’t that, like, the whole point of a password manager?


how they want to make those attesters trustworthy

It’s all derived from hardware security modules like TPM. It’s not impossible to exfiltrate private keys from these devices, but it’s difficult and expensive, involving de-lidding the chip and carefully reading electric charge values from individual flash gates. Not out of reach for a sophisticated state-sponsored targeted attack, but certainly puts Evil Maid and other opportunistic attacks out of reach.

As for how original integrity is established, that’s done by saving the public key or equivalent while the device is in the possession of the trusted entity.