Protecting systems with the TPM
Protecting systems with the TPM
Posted Feb 12, 2016 8:49 UTC (Fri) by jezuch (subscriber, #52988)In reply to: Protecting systems with the TPM by dlang
Parent article: Protecting systems with the TPM
> Except if you need high performance, at which point you get Self Encrypting Disks, SSDs that do the encryption on the drive itself.
Well, the drive has to run the encryption on *something* too. I guess the controller has some specialized hardware for that but still...
That said, I don't think I trust the on-drive encryption. It may be better in that the /boot will be encrypted as well, but since nobody can lift the hood and look inside the firmware, I think I'll stay with LUKS :)