Show HN: An eBPF kernel guard for vTPM access
By bschaatsbergen · 2026-10-04 · 4 points · 0 comments
https://github.com/bschaatsbergen/tpmlsm
A kernel guard I prototyped after eBPF and vTPM work for a customer, where we use the TPM to protect the private keys for mTLS. Any process running as root can open the TPM devices, and so can any process in the `tss` group, through `/dev/tpmrm0`. That means they can u…
Open the full discussion on BetterNews