3 ms·
> The TPM cannot prevent that Wait, why? I mean, they would be able to access the TPM, sure, but not the keys that would unlock the hard drive. This was my und
by graynk 6y ago
> The TPM cannot prevent that
Wait, why? I mean, they would be able to access the TPM, sure, but not the keys that would unlock the hard drive. This was my understanding when I played around with TPM: if the boot order has changed, no keys are given to the running OS. You can only reset them, but that just leaves you with an encrypted hard drive and no password to unlock it. I've only used it with LUKS though, not with Windows, but it'd be weird if the approach was different