etminan
Blog

Engineering & design, in depth.

Longer-form writing from the team building Etminan — the trust model, the decisions behind it, and the honest limits. For per-release “what shipped” notes, see News instead.

📡  Subscribe via RSS
Console 2026-10-03 ~7 min read

Browser, desktop app or terminal? Why the Etminan console is a TUI

The screen an operator approves trust from is part of the security boundary. A browser GUI, a native app and a terminal UI compared by what each adds to the box that decides trust — why we chose the terminal, what it costs us, and where the console stands.

Read the post →
Regulation 2026-08-17 ~9 min read

The Cyber Resilience Act and the machines you build on

The CRA's essential requirements describe a product — but several of them can only be true if the environment that produced it was itself intact, and Annex VII asks for your production processes and their validation. Which requirements reach that far, what each actually asks for, and, for each, how far host attestation reaches and where it stops.

Read the post →
Threat model 2026-08-05 ~9 min read

An AIDE alternative for when root is the adversary

AIDE is good software — the question is whether the threat you've written down is one any on-host checker can answer. The five moves an attacker with root makes, in order, and which ones a hardware root of trust blocks. Including move 04, the one that defeats an off-host database too, and an honest look at where AIDE still earns its keep.

Read the post →
Trust model 2026-07-27 ~8 min read

File integrity monitoring that's actually tamper-proof — what that really requires

“Tamper-proof” is the most over-claimed phrase in file integrity monitoring, and against a root compromise it's usually not true. The honest target is tamper-evident: changes you can't hide from something the host can't reach. What that takes — a hardware root of trust and an off-box verdict — plus a five-question checklist to hold any FIM vendor to.

Read the post →
Attestation 2026-07-25 ~9 min read

Offline-verifiable TPM attestation for Linux — no cloud, no third-party registrar

On-box integrity checkers let a compromised host suppress its own alarm. Etminan splits the job across two trust domains — a TPM on the host, an offline verifier that makes every decision — and the verifier needs no TPM of its own. How the quote-and-replay loop works, why the verifier is a TPM-less static binary, and the threat model stated plainly.

Read the post →

More to come — the tpm_wire.rs story, attestation that works air-gapped, and tamper-evident host integrity an auditor can read: ISO 27001, NIS2, DORA, SOC 2, PCI-DSS. Subscribe via RSS above to get them as they land.