2 ms·
That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely. Basically if any bug surfaces in the encryp
by lostmsu 2mo ago
That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely.
Basically if any bug surfaces in the encryption setup snap permanently loses the ability to update kernel, which, if you care about security, means the system has to be reinstalled to resume receiving kernel bug fixes. The issue is in "Wishlist".
https://bugs.launchpad.net/snapd/+bug/2045417 https://bugs.launchpad.net/snapd/+bug/2045417
- evan_a_a 2mo agoFar better to just use the raw tools and manage it yourself ala arch wiki: https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR_policies https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...
- lostmsu 2mo agoThe problem with manuals like that is they are like commercial flight checklists, except in most cases the user is not a professional pilot.
- sneakerblack 2mo agoSkill issue Jokes aside, I agree on the sense that this should be a solved problem. On the other hand, if the only implementation is a broken one, there's only one way to help yourself, and that is learning how to do it and helping yourself
- deleted 2mo ago[deleted]