Sunday, 4 October 2026

Show HN: An eBPF kernel guard for vTPM access https://bit.ly/4hH6UqP

Show HN: An eBPF kernel guard for vTPM access A kernel guard I prototyped after eBPF and vTPM work for a customer, where we use the TPM to protect the private keys for mTLS. Any process running as root can open the TPM devices, and so can any process in the `tss` group, through `/dev/tpmrm0`. That means they can use those keys too. This is a prototype and some research into protecting this path. https://bit.ly/4hLfDZa October 4, 2026 at 10:34PM

No comments:

Post a Comment