10 ms·
TPM-backed Full Disk Encryption is coming to Ubuntu
- Jigsy 3y agoAlthough I use Xubuntu on an old laptop, I'm hoping this is an option rather than a "suck it up!" change. I'd rather just enter a password...
- theandrewbailey 3y agoI'm in the process of moving away from Ubuntu, but this is a pretty cool feature. I've seen a tutorial here and there about how to manually set up LUKS with a TPM, but those have a downside of the TPM needing to be updated with every new kernel. I guess Ubuntu has found a way to integrate or work around that?
- wiktor-k 3y ago> but those have a downside of the TPM needing to be updated with every new kernel. This depends on the configuration. If you don't bind the key to PCRs at key creation time kernel updates don't affect the workflow and you still will take advantage of other TPM features such as locking the key after several unsuccessful attempts. Take a look at the systemd configuration: https://www.freedesktop.org/software/systemd/man/systemd-cryptenroll.html https://www.freedesktop.org/software/systemd/man/systemd-cry... I'm using it on my laptop and it works well.
- jandrese 3y agoIMHO the PCRs are way too much trouble and defend against attacks that are rare outside of extremely spooky circles. They were the biggest problem with Bitlocker too.
- alexeldeib 3y agoYeah, I recently went down this path. It’s all doable but frankly I’m not a nation state target and getting locked out after a kernel update or similar would be far more annoying. Instead I’m leaning toward separate boot and root disks, with a root/data disk encrypted with LUKS with a detached header. dm verity on a read only root with a separate data partition also seems simple/appealing. Of course, these all allow attacks full secure boot/tpm/etc avoid, but it’s a balance.
- wiktor-k 3y agoPCRs being problematic was actually one of the issues policy mechanism in TPM 2.0 was meant to resolve (see "Non-Brittle PCRs (New in 2.0)" in [0]). Tldr version is that you'd authorize OS manufacturer's kernel signing key to use the TPM key so that each time your OS vendor signs the kernel it's OK for the TPM. Sadly I don't think I've seen this deployed in the wild. [0]: https://ebrary.net/24725/computer_science/quick_loading https://ebrary.net/24725/computer_science/quick_loading
- FirmwareBurner 3y agoThat's groovy baby, but can anyone give me the technicals on why we can't have Hibernate(not sleep) out of the box on Ubuntu like we can on Windows? That was one of the deal-breakers for me making the switch. If I understood it correctly, it's because of Z-RAM and if I'm also correct, full disk encryption is another roadblock in the path of the hibernate feature.
- criddell 3y agoWindows these days prefers what they call modern standby and you probably don't want it. I have a ThinkPad and this is what it's like: Close the lid and stuff laptop into my backpack. I travel to work and when I pull my machine out of my bag, it has 12% battery left, is super hot, and the fan is screaming like the machine is trying to fly away. All because Microsoft thinks PCs should be more like iPhones.
- FirmwareBurner 3y ago>Windows these days prefers what they call modern standby and you probably don't want it. Who cares what Windows prefers, when I'm the user and I prefer Hibernate which works out of the box and I use it precisely because it avoids the issues you mentioned. Why don't you use Hibernate? SSDs are fast enough that a wake from hibernate is not much slower than a wake from sleep. On Ubuntu I don't even have this option because ... reasons.
- criddell 3y agoWindows can wake itself from hibernate. Killing all of the wake timers and editing specific keys in the registry will usually fix this, but it's messy and not something typical users are comfortable doing.
- FirmwareBurner 3y agoWhat do you mean? Hibernate works out of the box. There nothing to "fix" in the registry for that to work.
- michaelt 3y ago> the bootloader (shim and GRUB) and kernel assets will be delivered as snap packages (via gadget and kernel snaps), as opposed to being delivered as Debian packages. And there it is. I suppose having your kernel command line signed by Canonical and unmodifiable by the system owner without a pain-in-the-ass manual 'machine owner key enrolment' process is very much on-brand for Snap.
- nine_k 3y agoLooks perfectly aligned with corporate and especially government IT practices. There the user is by far not the owner.
- cgb223 3y agoSo if Ubuntu is pivoting hard into big corporate/govt Who’s the new big community desktop distro?
- Xiol32 3y agoPerhaps not exactly 'community distro', but Fedora is genuinely a joy to use.
- nine_k 3y agoNo idea! Debian proper? Fedora? Nix? Arch?.. (I personally run a relatively niche distro, https://voidlinux.org/ https://voidlinux.org/)
- sam_lowry_ 3y agoArch
- f_devd 3y agoVoid's great although definitely for the tinker crowd (like arch was), debian seems like the better community choice
- briffle 3y ago
- fatfingerd 3y agoWhat's the status for ZFS with a TPM and his will this affect it (competitively?)
- josephcsible 3y agoThis sounds like TPM and passphrase (as opposed to TPM or passphrase) which seems like a recipe for eating your data.
- tbyehl 3y agoOnly 11 years behind Windows 8 making BitLocker w/ Secure Boot easily accessible to the masses. Presumably not supporting TPM 1.2, which is why my oldest hardware runs Linux under Hyper-V instead of bare metal.