🔒 Hardware Security, Cryptography & Bootloaders
Air-gapped and hardware-bound security primitives ensuring cryptographic verification from pre-OS bootloaders to Linux userland secrets.
graph TD subgraph Hardware["Physical Security Primitives"] Key["FIDO2 / U2F Hardware Keys<br><i>Touch / User Presence</i>"] Storage["Encrypted USB Storage<br><i>Ventoy Verified Signatures</i>"] end subgraph CryptoLayer["Cryptographic Orchestration"] AgePlugin["age-plugin-fido2prf<br><i>Symmetric ECDH / HMAC</i>"] PAM["Linux PAM Module<br><i>Hardware-Enforced Auth</i>"] end subgraph Bootloader["Pre-OS Execution"] Kexec["kexecboot.xyz<br><i>WPA2/3 Wireless Fast-Pivot</i>"] Kernel["Direct Memory Ingestion<br><i>Zero-Disk Kernel Pivot</i>"] end Key --> AgePlugin Key --> PAM Storage --> Kexec Kexec --> Kernel
🏛️ Hardware Security Projects Portfolio
1. Hardware-Hardened Secret Management (FIDO2 + Age + Chezmoi)
Physical FIDO2 key derivation (age-plugin-fido2prf) binding symmetric encryption to hardware tokens with dual-recipient master recovery and zero plaintext exposure.
2. FIDO2 Security Toolkit & Linux PAM Hardware MFA
Hardware-hardened key management toolkit implementing physical touch verification for sudo authorization, SSH key residency, and automated token presence detection.
3. kexecboot.xyz: Wireless Network Bootloader
Pre-OS WPA2/WPA3 Wi-Fi authentication engine, dynamic netboot.xyz menu parsing, and direct in-memory Linux kernel kexec pivot bypassing traditional storage interfaces.
4. Ventoy Tech Super Tool: Multi-Boot USB Configuration
Multi-boot zero-trust USB environment engineered for live digital forensics, incident response triage, and cryptographically validated bare-metal system provisioning.
🧭 Navigation & Cross-Links
- Return to All Projects Master Catalog
- Review enterprise policies in Security & Governance
- Explore defensive counter-measures in Defensive Security