7 ms·
I don't fault Microsoft for increasing the security baseline, it's a fact that threats actors are getting smarter in general. If they did nothing, people would
by dngray 4y ago
I don't fault Microsoft for increasing the security baseline, it's a fact that threats actors are getting smarter in general.
If they did nothing, people would whinge that "Windows is so insecure". The reality is that Linux is starting to fall into this category. Having said that work on using the TPM has already taken place with systemd-cryptenroll and systemd-measure and it will be nice when "Legacy BIOS" is deprecated from most mainstream desktop distributions.
Maybe some day we will see some sort of immutable system that uses fs-verity, where "apps" are installed from an app store like Snap or Flathub. Then maybe we'll get some proper app sandboxing.
https://www.freedesktop.org/software/systemd/man/systemd-cryptenroll.html https://www.freedesktop.org/software/systemd/man/systemd-cry...
https://www.freedesktop.org/software/systemd/man/systemd-measure.html https://www.freedesktop.org/software/systemd/man/systemd-mea...
https://www.kernel.org/doc/html/latest/filesystems/fsverity.html https://www.kernel.org/doc/html/latest/filesystems/fsverity....