Hacker News new | ask | show | jobs
by cesarb 1416 days ago
Which is why the comment which started this sub-thread mentioned buying extra physical TPM 2.0 chips. They contain the correct keys, and since they're external devices, it's trivial to lie to them, pretending to be the physical CPU doing a normal boot.

Of course, that only works until they start rejecting external TPM chips, and accepting only the built-in "firmware" TPMs found in more recent CPUs.

1 comments

Yeah, Pluton "fixes" this because it's inside the CPU.