The solution is to use an HSM such as the Nitrokey/Purism Librem Key (same thing) that has a LED that lights up if boot integrity is fine, including a TPM secret matching (maid can't clone that).https://www.youtube.com/watch?v=O_3Xf3gTzEE
https://www.youtube.com/watch?v=K1O-33pi33M
https://www.youtube.com/watch?v=SB82Ul_A1js
rcthompson|4 years ago