|
|
|
|
|
by proto_lambda
962 days ago
|
|
With properly functioning secure boot and no bugs in the entire software stack, it doesn't matter if the disk is decrypted automatically, since you can't access the system without OS-level authentication. If you tried to replace system files to let you get in anyway, the secure boot measurements would no longer match up and the decryption fails entirely. |
|
So, data on a stolen laptop which has an unprotected TPM (no PIN to boot) can be considered compromised.