▲ 645 ▼ Fed-up Torvalds suggests disabling AMD’s 'stupid' performance-killing fTPM RNG (www.theregister.com) submitted 3 years ago* (last edited 3 years ago) by floofloof@lemmy.ca to c/linux@lemmy.ml 153 comments fedilink hide all child comments
[–] Ghast@lemmy.ml 50 points 3 years ago (7 children) I don't know why I keep hearing of security measures to stop someone sleuthing into bootloaders. Am I the only person using Linux who isn't James Bond? permalink fedilink source parent hideshow 14 child comments replies: [–] skullgiver@popplesburger.hilciferous.nl 38 points 3 years ago* (last edited 2 years ago) [This comment has been deleted by an automated system] permalink fedilink source parent [–] eager_eagle@lemmy.world 10 points 3 years ago (2 children) so you never caught a team of government officials in your living room brute forcing your bootloader at 4am as you got up to use the bathroom, huh. Lucky guy. permalink fedilink source parent hideshow 4 child comments replies: [–] TurtleTourParty@midwest.social 5 points 3 years ago* Your government doesn't just hit you with a wrench? permalink fedilink source parent [–] Shinhoshi@lemmygrad.ml 1 point 3 years ago Silly Lemmy user, it’s 4am and I’m on Lemmy permalink fedilink source parent [–] hansl@lemmy.ml 8 points 3 years ago (1 child) I’m an engineer with trade secrets on his laptop. I’ve heard of dozens of people getting laptops stolen from their cars that they left for like ten or fifteen minutes. The chances are slims, but if it happens I’m in deep trouble whether those secrets leak of not. I’m not taking the risk. I’m encrypting my disk. It’s not like there’s a difference in performance nowadays. permalink fedilink source parent hideshow 2 child comments replies: [–] duncesplayed@lemmy.one 5 points 3 years ago (1 child) TPM's not going to help with that situation, though, right? Either you're typing in your encryption password on boot (in which case you don't need TPM to keep your password), or you're not, in which case the thief has your TPM module with the password in it. permalink fedilink source parent hideshow 2 child comments replies: [–] pcouy@lemmy.pierre-couy.fr 2 points 3 years ago From what I understand, TPM is "trusted" because of the fact the secrets it contains are supposed to be safe from an attacker with hardware access. This is what makes it good at protecting data in case of a stolen laptop. This is also what makes it good at enforcing offline DRM or any kind of system where manufacturers can restrict the kind of software users can run on their hardware. permalink fedilink source parent [–] JuxtaposedJaguar@lemmy.ml 3 points 3 years ago It's 30% legitimate concern over a non-negligible risk of government overreach, 70% having fun pretending to be James Bond. permalink fedilink source parent [+] hansl@lemmy.ml 2 points 3 years ago [deleted] permalink fedilink source parent [–] MonkderZweite@feddit.ch 1 point 3 years ago I mean, i do have some stuff that i encrypt, but encrypting the folder or packing it on a small partitiin and encrypting only this fs after booting makes more sense to me. permalink fedilink source parent [–] The_Mixer_Dude@lemmus.org 0 points 3 years ago (1 child) I'm still on the hunt for a desktop Linux distro that has no security features or passwords. My usage for this may not be common but it can't be rare enough that there are zero options permalink fedilink source parent hideshow 2 child comments replies: [–] BlinkerFluid@lemmy.one 7 points 3 years ago (1 child) Ubuntu, no encryption, select boot to desktop by default when the system installs. Like, really? permalink fedilink source parent hideshow 2 child comments replies: [–] The_Mixer_Dude@lemmus.org 1 point 3 years ago (1 child) Still smashing in passwords left and right permalink fedilink source parent hideshow 2 child comments replies: [–] Moonrise2473@lemmy.ml 1 point 3 years ago Ah so you want the windows 98 experience, root access by default all the time without passwords or extra prompts. Maybe setting auto login and sudo without password can be almost enough? https://askubuntu.com/questions/147241/execute-sudo-without-password I agree that there should be an easy setting to at least allow updates without password. I installed Manjaro for my mom, after a while she complained "there are updates every day and I need to input the password too many times" permalink fedilink source parent
[–] skullgiver@popplesburger.hilciferous.nl 38 points 3 years ago* (last edited 2 years ago) [This comment has been deleted by an automated system] permalink fedilink source parent
[–] eager_eagle@lemmy.world 10 points 3 years ago (2 children) so you never caught a team of government officials in your living room brute forcing your bootloader at 4am as you got up to use the bathroom, huh. Lucky guy. permalink fedilink source parent hideshow 4 child comments replies: [–] TurtleTourParty@midwest.social 5 points 3 years ago* Your government doesn't just hit you with a wrench? permalink fedilink source parent [–] Shinhoshi@lemmygrad.ml 1 point 3 years ago Silly Lemmy user, it’s 4am and I’m on Lemmy permalink fedilink source parent
[–] TurtleTourParty@midwest.social 5 points 3 years ago* Your government doesn't just hit you with a wrench? permalink fedilink source parent
[–] Shinhoshi@lemmygrad.ml 1 point 3 years ago Silly Lemmy user, it’s 4am and I’m on Lemmy permalink fedilink source parent
[–] hansl@lemmy.ml 8 points 3 years ago (1 child) I’m an engineer with trade secrets on his laptop. I’ve heard of dozens of people getting laptops stolen from their cars that they left for like ten or fifteen minutes. The chances are slims, but if it happens I’m in deep trouble whether those secrets leak of not. I’m not taking the risk. I’m encrypting my disk. It’s not like there’s a difference in performance nowadays. permalink fedilink source parent hideshow 2 child comments replies: [–] duncesplayed@lemmy.one 5 points 3 years ago (1 child) TPM's not going to help with that situation, though, right? Either you're typing in your encryption password on boot (in which case you don't need TPM to keep your password), or you're not, in which case the thief has your TPM module with the password in it. permalink fedilink source parent hideshow 2 child comments replies: [–] pcouy@lemmy.pierre-couy.fr 2 points 3 years ago From what I understand, TPM is "trusted" because of the fact the secrets it contains are supposed to be safe from an attacker with hardware access. This is what makes it good at protecting data in case of a stolen laptop. This is also what makes it good at enforcing offline DRM or any kind of system where manufacturers can restrict the kind of software users can run on their hardware. permalink fedilink source parent
[–] duncesplayed@lemmy.one 5 points 3 years ago (1 child) TPM's not going to help with that situation, though, right? Either you're typing in your encryption password on boot (in which case you don't need TPM to keep your password), or you're not, in which case the thief has your TPM module with the password in it. permalink fedilink source parent hideshow 2 child comments replies: [–] pcouy@lemmy.pierre-couy.fr 2 points 3 years ago From what I understand, TPM is "trusted" because of the fact the secrets it contains are supposed to be safe from an attacker with hardware access. This is what makes it good at protecting data in case of a stolen laptop. This is also what makes it good at enforcing offline DRM or any kind of system where manufacturers can restrict the kind of software users can run on their hardware. permalink fedilink source parent
[–] pcouy@lemmy.pierre-couy.fr 2 points 3 years ago From what I understand, TPM is "trusted" because of the fact the secrets it contains are supposed to be safe from an attacker with hardware access. This is what makes it good at protecting data in case of a stolen laptop. This is also what makes it good at enforcing offline DRM or any kind of system where manufacturers can restrict the kind of software users can run on their hardware. permalink fedilink source parent
[–] JuxtaposedJaguar@lemmy.ml 3 points 3 years ago It's 30% legitimate concern over a non-negligible risk of government overreach, 70% having fun pretending to be James Bond. permalink fedilink source parent
[–] MonkderZweite@feddit.ch 1 point 3 years ago I mean, i do have some stuff that i encrypt, but encrypting the folder or packing it on a small partitiin and encrypting only this fs after booting makes more sense to me. permalink fedilink source parent
[–] The_Mixer_Dude@lemmus.org 0 points 3 years ago (1 child) I'm still on the hunt for a desktop Linux distro that has no security features or passwords. My usage for this may not be common but it can't be rare enough that there are zero options permalink fedilink source parent hideshow 2 child comments replies: [–] BlinkerFluid@lemmy.one 7 points 3 years ago (1 child) Ubuntu, no encryption, select boot to desktop by default when the system installs. Like, really? permalink fedilink source parent hideshow 2 child comments replies: [–] The_Mixer_Dude@lemmus.org 1 point 3 years ago (1 child) Still smashing in passwords left and right permalink fedilink source parent hideshow 2 child comments replies: [–] Moonrise2473@lemmy.ml 1 point 3 years ago Ah so you want the windows 98 experience, root access by default all the time without passwords or extra prompts. Maybe setting auto login and sudo without password can be almost enough? https://askubuntu.com/questions/147241/execute-sudo-without-password I agree that there should be an easy setting to at least allow updates without password. I installed Manjaro for my mom, after a while she complained "there are updates every day and I need to input the password too many times" permalink fedilink source parent
[–] BlinkerFluid@lemmy.one 7 points 3 years ago (1 child) Ubuntu, no encryption, select boot to desktop by default when the system installs. Like, really? permalink fedilink source parent hideshow 2 child comments replies: [–] The_Mixer_Dude@lemmus.org 1 point 3 years ago (1 child) Still smashing in passwords left and right permalink fedilink source parent hideshow 2 child comments replies: [–] Moonrise2473@lemmy.ml 1 point 3 years ago Ah so you want the windows 98 experience, root access by default all the time without passwords or extra prompts. Maybe setting auto login and sudo without password can be almost enough? https://askubuntu.com/questions/147241/execute-sudo-without-password I agree that there should be an easy setting to at least allow updates without password. I installed Manjaro for my mom, after a while she complained "there are updates every day and I need to input the password too many times" permalink fedilink source parent
[–] The_Mixer_Dude@lemmus.org 1 point 3 years ago (1 child) Still smashing in passwords left and right permalink fedilink source parent hideshow 2 child comments replies: [–] Moonrise2473@lemmy.ml 1 point 3 years ago Ah so you want the windows 98 experience, root access by default all the time without passwords or extra prompts. Maybe setting auto login and sudo without password can be almost enough? https://askubuntu.com/questions/147241/execute-sudo-without-password I agree that there should be an easy setting to at least allow updates without password. I installed Manjaro for my mom, after a while she complained "there are updates every day and I need to input the password too many times" permalink fedilink source parent
[–] Moonrise2473@lemmy.ml 1 point 3 years ago Ah so you want the windows 98 experience, root access by default all the time without passwords or extra prompts. Maybe setting auto login and sudo without password can be almost enough? https://askubuntu.com/questions/147241/execute-sudo-without-password I agree that there should be an easy setting to at least allow updates without password. I installed Manjaro for my mom, after a while she complained "there are updates every day and I need to input the password too many times" permalink fedilink source parent