How to build a reasonably secure t480s Thinkpad.
One major component to build a reasonably secure laptop, is the use of the Static Root of Trust for Measurements from your Trusted Platform Module.
But this functionnality comes with high risks:
If one hash in your PCRs tables comes to change, you won't be able to recover your data. (This could be an easy way to disrupt your hard work)
Before you start playing with some important stuff, you should consider a safe solution to store your data:
- version control system
- backup on personnal physical device
- cloud storage provider (with dual encryption)
- ...
- Free and open-source software
- Xen
- Security by compartmentalization
- Dom0: isolate from network
- Hardware Compatibility
- Necessary RAM