(no title)
vbezhenar | 21 days ago
That said, I think that it's better to use alternative approach. Use unencrypted signed system partition which presents login screen. After user typed their username and password, only user home gets decrypted. This scheme does not require TPM and only uses secure boot to ensure that system partition has not been altered. I think that macOS uses similar approach.
cookiengineer|21 days ago
If your laptop gets stolen, the thief also has your keys and can also decrypt the hard drive, which the TPM storage initially was supposed to have been invented for to actively prevent.
digiown|21 days ago
hparadiz|21 days ago
ndsipa_pomu|21 days ago
ab71e5|21 days ago