Hacker News new | ask | show | jobs
by michaelt 1011 days ago
I think a lot of Linux vendors have missed a trick by giving away TPM support for free.

I mean, the architecture of the TPM has more holes than swiss cheese, and a competent user can achieve higher security without using it.

There are clear benefits of the TPM for e.g. organisations so big that users forgetting their disk encryption password is a substantial support issue; corporations making TiVo-ized products that want to lock out the device owner; and corporations that need to comply with security requirements imposed by the technically clueless. Organisations who have bottomless pockets.

This seems like exactly the sort of features that belong in the Enterprise Edition of your product, like FIPS certification and SAML support.

1 comments

Indeed. So far TPMs so far have proven "useful" mostly in the restricted domain where the user is the threat vector. Ie. anchoring/hardening DRM.

Swiss cheese, disguised as protection against hackers, is merely great protection when fighting paying customers.