A kernel guard I prototyped after eBPF and vTPM work for a customer, where we use the TPM to protect the private keys for mTLS. Any process running as root can open the TPM devices, and so can any process in the `tss` group, through `/dev/tpmrm0`. That means they can use those keys too.

Source: [Hacker News](https://github.com/bschaatsbergen/tpmlsm)

Sponsored