3 ms·
That sentence is factually untrue. TPM does not prevent ransomware, despite what some people claim on Twitter. In fact, Bitlocker makes ransomware's job easier
by aj3 5y ago
That sentence is factually untrue. TPM does not prevent ransomware, despite what some people claim on Twitter. In fact, Bitlocker makes ransomware's job easier as now the whole disk is already encrypted and all you need (as a ransomware writer) to do is make encryption keys unusable (rotate keys through existing APIs, encrypt them on the disk or backup to c2 & overwrite).
Malware can still destroy or tamper with UEFI partition, Windows simply won't boot afterwards. Btw, tampering with Windows boot process is still possible - mainly due to many signed bootloaders (including some from previous Windows versions) which could be used to chainload something like minimal Linux initramfs containing KVM setup to run Windows with PCI passthrough (providing rw access to whole memory).