• Ghast@lemmy.ml
      link
      fedilink
      arrow-up
      54
      arrow-down
      4
      ·
      1 year ago

      I don’t know why I keep hearing of security measures to stop someone sleuthing into bootloaders.

      Am I the only person using Linux who isn’t James Bond?

      • Eager Eagle@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        1 year ago

        so you never caught a team of government officials in your living room brute forcing your bootloader at 4am as you got up to use the bathroom, huh. Lucky guy.

      • hansl@lemmy.ml
        link
        fedilink
        arrow-up
        8
        ·
        1 year ago

        I’m an engineer with trade secrets on his laptop. I’ve heard of dozens of people getting laptops stolen from their cars that they left for like ten or fifteen minutes.

        The chances are slims, but if it happens I’m in deep trouble whether those secrets leak of not. I’m not taking the risk. I’m encrypting my disk.

        It’s not like there’s a difference in performance nowadays.

        • duncesplayed@lemmy.one
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          1 year ago

          TPM’s not going to help with that situation, though, right? Either you’re typing in your encryption password on boot (in which case you don’t need TPM to keep your password), or you’re not, in which case the thief has your TPM module with the password in it.

          • pcouy@lemmy.pierre-couy.fr
            link
            fedilink
            arrow-up
            2
            ·
            1 year ago

            From what I understand, TPM is “trusted” because of the fact the secrets it contains are supposed to be safe from an attacker with hardware access.

            This is what makes it good at protecting data in case of a stolen laptop. This is also what makes it good at enforcing offline DRM or any kind of system where manufacturers can restrict the kind of software users can run on their hardware.

      • JuxtaposedJaguar@lemmy.ml
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        It’s 30% legitimate concern over a non-negligible risk of government overreach, 70% having fun pretending to be James Bond.

      • MonkderZweite@feddit.ch
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        I mean, i do have some stuff that i encrypt, but encrypting the folder or packing it on a small partitiin and encrypting only this fs after booting makes more sense to me.

      • The_Mixer_Dude@lemmus.org
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        1 year ago

        I’m still on the hunt for a desktop Linux distro that has no security features or passwords. My usage for this may not be common but it can’t be rare enough that there are zero options

    • interdimensionalmeme@lemmy.ml
      link
      fedilink
      arrow-up
      31
      arrow-down
      8
      ·
      1 year ago

      TPM bad, put your secrets on a proper encryption peripheral, like a smartcard running javacardOS

      TPM will turn into cpu-bound DRM, the more you use it, the more this cancer will grow

        • interdimensionalmeme@lemmy.ml
          link
          fedilink
          arrow-up
          8
          arrow-down
          10
          ·
          1 year ago

          You are only seeing what TPM is now. Not what TPM will become when it become an entire encrypted computing processor capable of executing any code while inspection is impossible.

          Imagine denuvo running at ring level -1

            • interdimensionalmeme@lemmy.ml
              link
              fedilink
              arrow-up
              4
              arrow-down
              3
              ·
              1 year ago

              Yes, it’s right in the name “trusted platform module”. There is no secret that their ambition is to become a space to run code outside the user’s reach and scrutiny.

              They start with the most legitimate and innocuous purpose. Once it is adopted and ubiquitous it will not suffer the fate of the other attempts and rotting on the vine.

              Then surprise TPM 5.0 become full scale full speed trusted execution environment and it’s too late to do anything about it. Eventually , non trusted processing capability will be phased out and only Intel and signed code will run.

    • bouh@lemmy.world
      link
      fedilink
      arrow-up
      2
      arrow-down
      14
      ·
      1 year ago

      Why do you need full disk encryption in your day to day life? Are you a secret agent? I feel like that would give you our though.

      It’s not a matter that I would have nothing to hide, this defense is stupid. It’s a matter that you should use a security adapted to your need, because the cost doesn’t offset the benefit otherwise. And with disk encryption you will far more often be sorry than happy if you’re a normal person.

      • mplewis@lemmy.globe.pub
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        1 year ago

        Full disk encryption is something you really want to have when your computer is lost or stolen.

      • mackwinston@feddit.uk
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        edit-2
        1 year ago

        People are imperfect. People have left laptops full of personal and/or commercially sensitive data on trains or planes, had them stolen from cars and houses etc. Full disc encryption is a defence against data breaches especially for computers that are not bolted down. Or it might be as simple as a person not wanting the embarrassment of their porn stash being found.