Longer-form writing from the team building Etminan — the trust model, the decisions behind it, and the honest limits. For per-release “what shipped” notes, see News instead.
📡 Subscribe via RSSOn-box integrity checkers let a compromised host suppress its own alarm. Etminan splits the job across two trust domains — a TPM on the host, an offline verifier that makes every decision — and the verifier needs no TPM of its own. How the quote-and-replay loop works, why the verifier is a TPM-less static binary, and the threat model stated plainly.
Read the post →
More to come — the tpm_wire.rs story, attestation that works air-gapped, and
NIS2-grade tamper-evident host integrity. Subscribe via RSS above to get them as they land.