(no title)
emily-c | 2 years ago
DRTM, a technology supported by Windows 11 that is layered on top of the TPM, aims to solve this very problem.
emily-c | 2 years ago
DRTM, a technology supported by Windows 11 that is layered on top of the TPM, aims to solve this very problem.
hlandau|2 years ago
emily-c|2 years ago
While what you said is technically correct, it is by design and any compromised firmware can do as it pleases before the DRTM event at the cost of getting caught and having the device fail attestation or not be able to access encrypted data (depending on what policy is layered on top of DRTM itself as it is just a security primitive). By having PCRs get reset during the DRTM event secrets are much more reliably able to be sealed to specific PCR values.