11 ms·
Well, smartphones must be updated to include better spyware. And newer computers are also better locked down to allow better surveillance. So, the older ones
by emouryto 5y ago
Well, smartphones must be updated to include better spyware.
And newer computers are also better locked down to allow better surveillance.
So, the older ones can't break down fast enough!
You don't want a repairable computer so creeps install, like, a Linux distro. You want disposable TPM machines with Windows 11 Home Edition and unstoppable "telemetry".
- Someone1234 5y agoI feel like there's a large subset of people who don't understand what TPM does, so just assume the worst and hand wave about how it [somehow] causes [random bad thing]. In this case I guess TPM causes telemetry?
- Aeolun 5y agoNo, no, don’t mistake correlation with causation. They just always come together. Note: I have no idea what TPM even is.
- sascha_sl 5y agoIt's what Apple calls a "secure element", essentially a mini-HSM or multi-feature smartcard. "Put keys on it and it lets you use it with a PIN and rate limit" seems to be the main use case (they can implement FIDO2 with that too for instance). These things are very useful for authentication and have been on business laptops for this very reason forever.
- jandrese 5y agoA TPM is just a bit of memory that is "hacker proof" so you can store a private key with a guarantee that it can't leak out. You can then sign, encrypt, or decrypt using the key. They were controversial because it was originally thought they would be used to lock parts of your computer away from you, being used to do DRM and the like. At the end of the day the chips were hard to use, slow, and flaky enough that it didn't really pan out. A lot of the braindamage came from a secondary feature where you could theoretically create "secure enclaves" where the entire execution chain down to the bare metal was signed to prevent viruses and rootkits from executing. In theory this is neat, but in practice it's basically impossible on PC hardware and caused a lot of problems. This functionality is the reason BitLocker had the reputation for randomly locking you out of your machine, even though it doesn't use the feature directly. The configuration registers were maybe a mistake.
- meowface 5y agoI know it's super easy for anyone to Google, but I feel like at least one reader will find this useful since I didn't see it mentioned anywhere in the discussion thread: TPM stands for Trusted Platform Module. ("TPM is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys." - https://en.wikipedia.org/wiki/Trusted_Platform_Module https://en.wikipedia.org/wiki/Trusted_Platform_Module)
- tremon 5y agoA TPM is much more than "just a bit of memory". It is a cryptographic coprocessor, with its own microcode and its own security domain. And I don't think a fully-secured future for PC's is as impossible as you think. The primary reason this is impossible right now is because TPM's aren't ubiquitous (none of my machines came with one installed). That problem will be solved by Windows 11.
- jandrese 5y agoThe fundamental problem with the secure enclave on PC is that to make it work you have to basically lock out all of the untrusted hardware on the box, which is pretty much all of it. So while you are doing your secure computation nobody is servicing the PCIe bus. The graphics card drivers aren't getting any CPU cycles. Ring buffers on your network cards aren't emptied. From the perspective of everything else on the machine the whole thing just crashed. If your computation is quick you might be able to get away with this sometimes, but the potential for problems is almost unlimited. The fact that the TPM itself is pretty slow throws another monkeywrench into the plan. In order for it to work the whole system needs to be designed from the bottom up to support it, which means you need to touch every layer of the PC stack. It's a lot of work. It is a lot easier on something like a cellphone where you can control the hardware from top to bottom and don't have to consider the case where someone installs additional hardware to suit their needs.
- cmxch 5y agoSecured for the benefit of Microsoft or DRM providers, not necessarily for the benefit of the end user. Unless they're willing to allow the end user to override the wishes of the vendor (and without any diminished functionality), TPM is just another way to turn computers into appliances.
- gravstar 5y agoLol I think MOST people don't understand what TPM is/does...
- rocqua 5y agoTPM used for secure boot, (hypothetically) used to block installing non-windows OS, means the owner is forced to using an OS that has telemetry. That is the argument I suppose OP was making. The secure boot locking is hypothetical, but it is often feared. I get why, because it seems like something Microsoft would love to do.
- my123 5y agoTPM is used for measured boot, to not release a secret/operate on a key if measurements do not match. It doesn't block you from running anything.
- rocqua 5y agoDang your right. I figured the TPM was part of secure-boot validation. But given some extra thought, it is clear that verifying a signature does not require any secrets.
- layoutIfNeeded 5y ago>It doesn't block you from running anything. Yet
- okennedy 5y agoA TPM is a chip on some motherboards that serves two purposes: 1. Using something not too dissimilar from blockchain/git repo hashes to attest to the the execution stack (BIOS, bootloader, kernel, userspace). 2. Providing cryptographic primitives that are only unlocked when the stack exactly matches a particular value. It's a handy tool for avoiding spyware, as any change in the attestation chain gets immediately flagged. It is also, in principle, useful for tying DRM keys to a particular execution stack that's known to be trusted... although it's very worth noting that the TPM's threat model does not include an attacker having physical access to the hardware.
- 2OEH8eoCRo0 5y agoI thought TPMs also prevent physical attacks by being configurable to require password for unlock and physical anti tamper features.
- als0 5y agoThe bus between the CPU and the TPM is exposed, so there are plenty of physical attacks that you can do, assuming a certain level of skill and tools.
- 2OEH8eoCRo0 5y agoRight, for configurations where the tpm automatically releases keys, they can be sniffed. It can be configured to only release it's secret once a correct password is given. It also rate limits I believe.
- zwarag 5y agoIf history is an indicator for anything, we’re talking about when. Not if.
- heavyset_go 5y agoStallman[1] and others[2] wrote about TPMs nearly 15 years ago, and the former revisited the topic in 2015. Trusted Platform Modules can be used enforce app DRM, ensuring that only "approved" apps are able to run on a system. That's already the reality for iPhones and iPads. We see desktops converging on this reality with systems like Apple's M1 which won't run unsigned binaries at all, and makes it difficult to nearly impossible to run apps that weren't first approved by Apple through their notarization process. [1] https://www.gnu.org/philosophy/can-you-trust.en.html https://www.gnu.org/philosophy/can-you-trust.en.html [2] https://www.cl.cam.ac.uk/~rja14/tcpa-faq.html https://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
- fsflover 5y agoTPM can be based on free software and controlled by the user: https://puri.sm/posts/purism-integrates-heads-security-firmware-with-tpm-giving-full-control-and-digital-privacy-to-laptop-users/ https://puri.sm/posts/purism-integrates-heads-security-firmw....
- heavyset_go 5y agoThanks for the link, I wasn't aware of Purism's work in this space. Is an open and flashable TPM something rights holders would be comfortable with? Or would they treat it like SafetyNet treats an Android phone with an unlocked bootloader?
- Spivak 5y agoYes but that isn’t the main point. When combined with a non-free OS TPMs become a tool used against the user to lock them out of their own system.
- fsflover 5y agoYou are right. The problem however is not in the TPM but in the non-free OS.
- marcosdumay 5y agoThe main point (and only differential) of a TPM is protecting secrets against the person with physical possession of the device. About every time something like this is placed on a consumers product, it is to exploit the consumer some way, so, no it's just bad. There is the very rare exception of it being a product intended for the owner to lend it to other people, and the very common exception of it being disabled by default, but being cheaper to include on every product than just the business ones. But well, Windows 11 Home edition computers are neither of those.
- plainnoodles 5y agoTo be fair, TPM's are really cool from a hardware perspective. They're HSM's which can fundamentally change what threat models on your OS look like. Unfortunately, the purpose here will be to use the fact that most users use a non-free OS to turn these TPMs against the user in order to make DRM harder to break.
- toast0 5y agoI see the value in using a TPM to protect a disk encryption key; but also the downside of it being harder for me to recover data when the TPM fails before the disk (or if the motherboard fails and the TPM is tamper resistant and doesn't want to be moved to another board, etc). For me, data recovery is more important. Boot time security sounds kind of useful, but I don't have time or desire to audit and sign everything I run, and Microsoft doesn't either; they have historically signed all sorts of garbage that undermines the system security, and I expect that will continue.
- tenebrisalietum 5y agoI think this is why you don't store the encryption key of the disk directly in the TPM but a "key to unlock the key" - that way you can enter a recovery code or something to access if the TPM or something in the boot path fails. I don't know how the encryption mechanics work in detail but it has to work like that somehow for Bitlocker recovery to function. I know under Linux LUKS you can have up to 8 keys and each will allow access to the disk.
- at-fates-hands 5y agoJust in case someone wants to know what a TPM is: Trusted Platform Module, or TPM, is a unique hardware-based security solution that installs a cryptographic chip on the computer's motherboard, also known as a cryptoprocessor. This chip protects sensitive data and wards off hacking attempts generated through a computer's hardware. Each TPM holds computer-generated keys for encryption, and most PC's nowadays come with TPM chips pre-soldered onto the motherboards.
- alerighi 5y ago
- ezconnect 5y agoMy Windows 10 Pro just got updated to Windows 11 for free via an update and I have no TPM module.
- hvdijk 5y agoWindows 11 previews do not require a TPM module, but the final Windows 11 will. Quoting from https://blogs.windows.com/windows-insider/2021/06/28/update-on-windows-11-minimum-system-requirements/ https://blogs.windows.com/windows-insider/2021/06/28/update-...: > In support of the Windows 11 system requirements, we’ve set the bar for previewing in our Windows Insider Program to match the minimum system requirements for Windows 11, with the exception for TPM 2.0 and CPU family/model.
- alerighi 5y agoSo I can install Windows 11 previews, then when the definitive version comes out I would need to downgrade if I don't have a TPM hardware (or if I don't want to enable it for not loosing the possibility to dual boot Linux)? It's nonsense. I want the old Windows back, couldn't Microsoft just stop making OS and support Windows 7 forever? The last Windows version that just worked, buy a license and use it, no updates every 6 months, no requirement for secure boot, TPM and stupid stuff, no apps, or whatever other stupid thin they invented.
- hvdijk 5y ago> then when the definitive version comes out I would need to downgrade if I don't have a TPM hardware Yes, if you do not have TPM hardware you will not be able to run Windows 11 when it is released. > (or if I don't want to enable it for not loosing the possibility to dual boot Linux)? TPM does not prevent you from installing or running Linux.
- sunshineforever 5y agoAmen