218
submitted 1 month ago* (last edited 1 month ago) by misk@sopuli.xyz to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] NeoNachtwaechter@lemmy.world 10 points 1 month ago

This one big question around the T in TPM, has anyone found a satisfying answer yet?

T is for "trusted". So far it was easy.

But who is supposed to trust whom?

The only case I found plausible so far is, that M$ can now decide whether or not they want to trust your PC (against you, the user).

[-] towerful@programming.dev 16 points 1 month ago

I'm sure this is a meme, but the trust is proving the OS is not tampered with.
Like, if malware was able to inject a malicious windows update URL into the OS, and inject a malicious certificate that gets the OS to trust the malicious updates by the malicious URL.
The signature of the OS would then differ from what the TPM/CPU recorded during OS boot and what the TPM/CPU has hashed during running. This would indicate that the OS has been tampered with.
So the trust in TPM is that the TPM and CPU are working together correctly (which is certified during manufacturing), so that the TPM can then attest that the OS (or software or whatever) hasn't been tampered with.

So yeh, it's MS (or whatever software company) trusting that the software it is interacting with is running as it is intended

[-] catloaf@lemm.ee 9 points 1 month ago

Honestly, the user is the biggest security risk in the first place. People run all kinds of malware and put their passwords into phishing sites all the time. One thing a TPM is used for is secure boot, which prevents malware from inserting its own bootloader to take over the OS.

[-] NeoNachtwaechter@lemmy.world -5 points 1 month ago

the user is the biggest security risk

Of course LOL

The user of a hammer is the only one who can destroy the hammer. Humans on the planet's surface are the only ones who can destroy the planet... we should definitely separate the human user from his rights and freedom, shouldn't we?

[-] Traister101 2 points 1 month ago

Interesting direction to go...

[-] SpaceCadet2000@kbin.social 6 points 1 month ago

But who is supposed to trust whom?

12 years old and still relevant:
https://www.youtube.com/watch?v=s7WDbnHlc1E

[-] PipedLinkBot@feddit.rocks 2 points 1 month ago

Here is an alternative Piped link(s):

https://www.piped.video/watch?v=s7WDbnHlc1E

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I'm open-source; check me out at GitHub.

[-] RobotToaster@mander.xyz -1 points 1 month ago
this post was submitted on 26 May 2024
218 points (97.4% liked)

Technology

55692 readers
2807 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS