• TurboWafflz@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 months ago

        What makes TPM+pin safer than just having a normal LUKS password? I would think it would be the same amount of security just with more chance of data loss if your computer gets damaged

      • Tenderizer78@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        edit-2
        3 months ago

        As I understand it the TPM is for people who have physical access. It prevents them from cloning your disk.

        I think with an adequately long password (or an adequately resource-intensive encryption algorithm) you can secure your disk enough to prevent unauthorized access. But the TPM would prevent them from removing your hard-drive and shunting it into a super-computer (so all password attempts wouldn’t need to be on the crummy 10-year old laptop CPU) so a TPM + password is more secure.

        • pmk@lemmy.sdf.org
          link
          fedilink
          arrow-up
          2
          ·
          3 months ago

          I’ve read the arguments and trust the people who know far more than I do about this, but… I just find it difficult to think of “unlocks automatically” as more safe than “is locked until I enter my password”. I’m open for it, but it just feels strange to me.