Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Didn't Tailscale try to do something similar but found out quickly that TPMs 1) aren't as reliable as common wisdom makes them out to be, and 2) have gotchas when it comes to BIOS updates?

I can't find it now, but I believe someone from Tailscale commented on HN (or was it github?) on what they ran into and why the default was reverted so that things were not stored in the TPM.

EDIT: just saw the mention in the article about the BIOS updates.



If you run into the link to this, is love to read it. Proper, modern, pcrphase binding with a signing key should remove these firmware update issues irt the raw pcr value changing


Yep, found the relevant links:

https://github.com/tailscale/tailscale/issues/17622

https://news.ycombinator.com/item?id=46532666 (direct comment link, more discussion on the issue in the parent)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: