Hacker News new | ask | show | jobs
by ufmace 1789 days ago
Ah yeah that makes more sense. I suppose managing FDE key via TPM is theoretically / ideally more secure, but has a lot more attack surface. Probably not many TPM implementations have been attacked enough publicly for anyone to be confident they're actually more secure than a regular password with good modern KDF.