• TurboWafflz@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      What makes TPM+pin safer than just having a normal LUKS password? I would think it would be the same amount of security just with more chance of data loss if your computer gets damaged

    • Tenderizer78@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      edit-2
      3 months ago

      As I understand it the TPM is for people who have physical access. It prevents them from cloning your disk.

      I think with an adequately long password (or an adequately resource-intensive encryption algorithm) you can secure your disk enough to prevent unauthorized access. But the TPM would prevent them from removing your hard-drive and shunting it into a super-computer (so all password attempts wouldn’t need to be on the crummy 10-year old laptop CPU) so a TPM + password is more secure.

      • pmk@lemmy.sdf.org
        link
        fedilink
        arrow-up
        2
        ·
        3 months ago

        I’ve read the arguments and trust the people who know far more than I do about this, but… I just find it difficult to think of “unlocks automatically” as more safe than “is locked until I enter my password”. I’m open for it, but it just feels strange to me.