this post was submitted on 13 Dec 2024
942 points (98.6% liked)

linuxmemes

21601 readers
364 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't fork-bomb your computer.

    founded 2 years ago
    MODERATORS
     
    you are viewing a single comment's thread
    view the rest of the comments
    [–] [email protected] 21 points 1 week ago (2 children)

    Can i get some context please? My fedora install wasn't using TPM, i had to manually configure it; i haven't noticed any difference in boot speed with or without TPM encryption

    [–] [email protected] 1 points 1 week ago (1 children)

    Why wouldn't you just use a password?

    [–] [email protected] 3 points 1 week ago (1 children)

    I want to have data-at-rest encryption, so that the only password i need to insert is my user one, this allows me to not have to type passwords multiple times. If i had the regular encryption password i would have to enable autologin in SDDM, which would do away with the encryption on kdewallet and all my credentials.

    Plus i also enable secureboot, and use fedora kinoite, so that i is hard to tamper with my boot stuff without my TPM wiping itself off my encryption password, this gives me a very Bitlocker-like setup, but without the shittiness of having my encryption keys linked to microsoft's terrible encryption system and user accounts, i can actually control my stuff like this. For a laptop, i must say data-at-rest encryption is a must!

    This setup gives me multiple security layers; took my laptop off me -> booted my laptop, faced with user password -> tried to boot another OS, TPM wiped itself, no more encryption key -> computer now asks for encryption password, has to find a way around LVM2 encryption -> LVM2 encryption (somehow) defeated they must now crack my user password, or have to (try) to decrypt my credentials on the file system itself; after all these convoluted and extremely hard steps i think we can agree this person really deserves to have access to my cool wallpapers

    [–] [email protected] 2 points 1 week ago (1 children)

    Secure boot and TPM aren't known for there robust security. In fact, I'd wager that your machine is probably vulnerable.

    https://www.bleepingcomputer.com/news/security/bootkitty-uefi-malware-exploits-logofail-to-infect-linux-systems/

    Or for that matter, it is possible that your secure boot keys have been leaked or that your TPM is vulnerable to sniffing.

    [–] [email protected] 1 points 1 week ago

    Yeah, i know; EUFI computers really suck, turning away the script kiddies and most people that would steal this computer from my data is is the most i can with this thing

    [–] [email protected] 1 points 1 week ago (1 children)

    Probably only affects a small number of AMD machines.

    [–] [email protected] 1 points 1 week ago* (last edited 1 week ago)

    so if it probably affects only a small number of specific hw platforms, you cannot state fedora as "now wait 40 seconds" distro.

    i'm also not using the tmd chip, no issues.