I use PopOS and I wonder does the TPM processor in my CPU get used for anything out of the box? If not, what could it be used for? Have you guys got practical advice?
I use PopOS and I wonder does the TPM processor in my CPU get used for anything out of the box? If not, what could it be used for? Have you guys got practical advice?
This is probably the main reason every mainboard has TPMs now, since all common operating systems (Android, iOS/MacOS and Windows) do it.
From what I heard the Ubuntu installer offers a version that doesn’t suck (if secure boot is enabled at install time) so using that is probably fine, but I would beware of trying to DIY it since it’s easy to do incorrectly, most guides are wrong, and you will likely end up with easily bypassable encryption.
Thankfully I don’t even trust TPM, so I just use regular passphrase unlock. This has added benefit of password expiration if unused (I will forget it eventually).
What about it do you not trust, out of curiosity? And how do you ensure OS integrity if not using TPM?
TPM is great on paper, but in practice, there was little planning to ensure that cryptographic keys would be safeguarded by hardware manufacturers, and that’s exactly what happened. Now TPM is considered weak as a means of securing data.
https://www.tomshardware.com/software/security-software/secure-boot-key-compromised-in-2022-is-still-in-use-in-over-200-models