this post was submitted on 22 Jun 2023
46 points (100.0% liked)
Technology
37702 readers
287 users here now
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It disallows certain attacks other people could perform on your devices. I've already explained this in 2 other comments in this thread.
Firstly, even with physical access to your device, it'll be harder to fuck with the firmware or software on your computer. Windows literally can't unlock your data if something's fucky, because TPM won't give it the required keys. Secondly, TPM can be used as a more secure way to store encryption keys in general. And thirdly, you get hardware random number generation, which can be very useful if your system's entropy is too low.
Yes, unfortunately it also means DRMs can force you to consume content on only the exact same hardware you purchased it for. But there ARE legitimate use cases for TPM too. TPM has been used in enterprise settings for over a decade.
Luckily for now at least, there's a solution for the whole DRM issue too. It's called piracy. Plenty of DRM free content out there. It's possible that some streaming content literally won't reach your favourite torrent site because hardware DRM, but I'm not TOO worried about it personally, because HDCP can be bypassed, so there's still a way to capture the signal, it's just between the computer and the screen.
But overall, definitely use Linux instead of Windows with TPM off if you're worried about ANY of this. And I mean, sure, keep TPM off, it's highly unlikely that you'll actually need the niche extra security it provides on a personal device.
The only one with physical access to my hardware trying to fuck with the software is me. Evil maid attacks are purely hypothetical for almost everyone, and suggesting that TPM is necessary to protect against them is dishonest. TPM is a much greater threat than any it purports to protect against.
Almost everyone just means home users and those don't matter much to Microsoft anyway, corporate is where the big money is.