Hello,
Can you take advantage of the security benefits of Boot Clock Randomization even when sdwdate is disabled?
Any Help would be appreciated.
Hello,
Can you take advantage of the security benefits of Boot Clock Randomization even when sdwdate is disabled?
Any Help would be appreciated.
Yes, because these are completely separate packages.
This is a problem for 2FA based on TOTP, unless the software runs its own independent clock, I don’t know of any that do that.
In that case, you need to disable both. Boot Clock Randomization and
sdwdate. In that case, you might be better off using an offline VM
(“vault”).
I have an Debian installation without kicksecure, but I notice that when I disable NTP services weeks later, the clock goes off by a few seconds, I notice this when the TOTP codes stop working.
is this common? well, that would explain why computers constantly synchronize their time
happens with any software if the time is not synchronized with the real time.
for example, if the time is one minute ahead or one minute behind keepass will not function correctly.
Not sure what you definition of “normal” is.
But to be expected: yes.