|
|
|
|
|
by patrakov
1203 days ago
|
|
It is not because of an unencrypted swap partition. It is because, even if it is encrypted, you know the key and can thus replace the image with an arbitrary modified one, or, in theory, with a hacked version of a Windows boot loader, which would break DRM. There were some movements to remove this restriction, on the condition that the encryption key is properly sealed in the TPM and is not extractable. |
|
TPM has never been a pre-requisite for secureboot nor kernel_lockdown. Infact the proposal you are speaking of sounds very exclusionary since TPM hardware is still relatively new and not ubiqitous.