top 50 comments

sorted by: hot top controversial new old
[–] 337 points 3 years ago (38 children)

TPM is basically never for your benefit. It's becoming a requirement because Microsoft is going to one day say "you can only run apps installed from the Windows Store, because everything else is insecure" and lock down the software market. Valve knows this which is why they're going so hard on the Steam Deck and Linux.

  • source
  • hideshow 43 child comments
  • [–] 175 points 3 years ago* (last edited 2 years ago) (8 children)

    [This comment has been deleted by an automated system]

  • source
  • parent
  • hideshow 11 child comments
  • [–] 115 points 3 years ago (5 children)

    This is why I keep my initrd tattooed as a barcode on my testicles.

  • source
  • parent
  • hideshow 10 child comments
  • [–] 50 points 3 years ago (12 children)

    I don't know why I keep hearing of security measures to stop someone sleuthing into bootloaders.

    Am I the only person using Linux who isn't James Bond?

  • source
  • parent
  • hideshow 14 child comments
  • load more comments (10 replies)
  • [–] 23 points 3 years ago (1 child)

    TPM bad, put your secrets on a proper encryption peripheral, like a smartcard running javacardOS

    TPM will turn into cpu-bound DRM, the more you use it, the more this cancer will grow

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (5 replies)
  • [–] 30 points 3 years ago (1 child)

    https://hothardware.com/news/steam-deck-tpm-support-install-windows-11

    I mean I generally agree with you, but the SteamDeck runs on an AMD processor with a fTPM that Valve slowly added support for.

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 25 points 3 years ago* (9 children)

    It seems unlikely Valve will ever make Windows the primary OS for their devices. And they'd lose a lot of user support if they ever required the TPM for their own software, so hopefully they wouldn't risk it.

  • source
  • parent
  • hideshow 11 child comments
  • [–] 31 points 3 years ago* (2 children)

    Why does everybody seem to think that userspace attestation is the only use for the TPM? The primary use is for data to be encrypted at rest but decrypted at boot as long as certain flags aren't tripped. TPM is great for the security of your data if you know how to set it up.

    Valve is never going to require TPM attestation to use Steam, that's just silly. Anti-cheat companies might, but my suggestion there is to just not play games that bundle malware.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (7 replies)
  • [–] 28 points 3 years ago (1 child)

    Support for old software is now the only reason to use windows.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 45 points 3 years ago (2 children)

    I'm a big fan of Linux, but I can't believe you really think this.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 3 years ago (3 children)

    Sadly, I agree. I'm at the point now where as long as I'm not trying to game I can thrive on Linux. But even then I spend way more time than necessary getting things to work that do so out of the box on Windows. We have a long way to go before legacy apps is the only reason to run it.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 17 points 3 years ago (2 children)

    Personally I found the time I saved from not having any control over my system has more than made up for tinkering that I have to do to get things running. My laptop would regularly become unusable for 20+ minutes on windows because of disk performance issues, and I as the user had no means to prevent windows from running the service that locked everything up. That along with other times windows just decides your use case is less important have added up to far more time then having to debug a game here and there

  • source
  • parent
  • hideshow 3 child comments
  • [–] 10 points 3 years ago (2 children)

    Ungh, yeah I used to have that problem with my laptop when I was in college.

    I only booted it up for classes unless I had a test coming up I needed to study for or something. Because why the fuck would I not do that - I had a regular computer at home for everything else.

    Every couple weeks, that meant it was updating instead of being available for note taking, and usually for the entire hour I needed it. Because apparently setting the updates to run during shutdown wasn’t good enough, they needed to be run on boot, because fuck you that’s why.

    Linux is just.. hey I should probably update this shit at some point… meh, tomorrow.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (1 reply)
  • load more comments (2 replies)
  • load more comments (33 replies)
    [–] 135 points 3 years ago (2 children)
  • load more comments (1 reply)
    [–] 87 points 3 years ago (7 children)

    I always just kill my TPM chip. It's so obvious tpm will be used in the future for application offline DRM. They will executed encrypted operations under the TPM veil and decompilers will become unusable.

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    [–] 80 points 3 years ago (1 child)

    I love how Torvalds always calls it like he sees it.

  • source
  • hideshow 2 child comments
  • [–] 57 points 3 years ago (2 children)

    Would love this. I'm still getting the ftpm stutters and there's no way to disable it in my motherboards bios.

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 51 points 3 years ago

    Based linus. Kill it, it's pointless

  • source
  • [–] 44 points 3 years ago (2 children)

    I've had a weird system-wide stutter for months and the usual googling and troubleshooting didn't help.. omg. This might be it. Thank you Linus and thank you op.

  • source
  • hideshow 3 child comments
  • [–] [S] 16 points 3 years ago* (3 children)

    I had it on my Windows 11 PC for a long time. I use this PC for music production and it was infuriating - the sound would just cut out intermittently like the computer couldn't keep up. I tried lots of things, including an expensive CPU upgrade. In the end Asus released a new BIOS for the motherboard to address this AMD stutter, and that fixed it.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • load more comments (1 reply)
    [–] 27 points 3 years ago (1 child)

    the module can cause intermittent stuttering, depending on which Ryzen processor you're using. It appeared when the fTPM was in use, it would access its flash storage via a serial interface, and when doing so, held up activity by the rest of the system.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 16 points 3 years ago (4 children)

    "Maybe use it for the boot-time 'gather entropy from different sources,' but clearly it should not be used at runtime."

    Good idea. Ask it during boot/insmod for some hardware-random bits to seed Linux's usual software-only CSPRNG, then just use that.

    And even that might not be a great idea. I wouldn't be surprised if the fTPM RNG is subtly not-entirely-random, at some alphabet agency's behest. I remember there being a controversy over rdrand for this reason…

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 13 points 3 years ago

    Yup. I've been wondering if that was the thing that's made the v6.4 kernels so unstable on Ryzen machines.

  • source
  • load more comments
    view more: next ›