Protecting systems with the TPM
Protecting systems with the TPM
Posted Feb 18, 2016 4:58 UTC (Thu) by ras (subscriber, #33059)In reply to: Protecting systems with the TPM by rahvin
Parent article: Protecting systems with the TPM
My last Dell two laptops (Precision and now XPS) do have TPM's, and I gather that is usually the case for "work" oriented Dell's.
You are right in saying it is a rare person that uses them (certainly I didn't) - but that has to come with a big qualification. It only applies to PC's. My phone has a TPM like thingy, and it is switched on by default. That isn't unusual. In fact in a few years I'd say most people will use hardware protect provided by a TPM like device every day of their lives.
When I ask myself why I am happy to use it on my phone but not my PC, the answer seems to be I am pretty confident I won't lose data on my phone due to the TPM. At least I haven't yet, and it's gone through a fair few firmware upgrades. On the other hand I have a friend who did turn on disk encryption for his Mac and one mishap or so later, he lost everything stored there. (It was backed up, but turns out Time machine encrypted the backup with the sealed key.) It happened to contain his wife's photo collection from an overseas holiday, so he wasn't a popular boy. Colour me skeptical, but if I ever get around turn on full disk encryption on Debian testing and seal the key with the TPM, I also fully expect to lose all the data on the disk; repeatedly.
If that expectation changes to me believing it works as well on my PC as it does on my phone, I would enable the TPM and full disk encryption as a matter of course, and I'd hope my distro would do that by default.
I guess the point I'm trying to make is that people do find TPM's useful, they only avoid them because they are too hard to use. Microsoft, Apple and Google are now doing an excellent job of making it obvious they don't have to be hard to use. It seems we in the open source world are learning how to deploy TPM's them, not the other way around.