Hacker News new | ask | show | jobs
by yellowapple 2538 days ago
So why can't I use a password to unlock my TPM module, then? Why does it have to be a PIN specifically?
1 comments

Presumably because people are less likely to think a PIN "secure" and "unguessable", and ironically are more likely to protect it (and actually remember it without writing it down). In general, people are really bad at passwords and password security. Microsoft here are taking the stance that the only good password is no password at all. There is a (weird) psychological difference between passwords and PINs.

(Also, it doesn't have to be a PIN, it can be biometrics if you prefer.)