|
|
|
|
|
by logical_person
1033 days ago
|
|
that's still less secure, though. without a TPM you have no guarantee of the underlying state of firmware on the device. this enables a persistent backdoor. TPM with no PIN is practically bitlocker with no password. A high entropy PIN happens to solve this entire attack. |
|
The PCRs attest system state to the OS, yes. Though the verified boot (PSB/Secure Guard + Secure Boot) chain is supposed to provide the same security there. Provided we assume security features aren't broken by design...