Hacker News new | ask | show | jobs
by Dowwie 864 days ago
Interesting...

A PIN auth step eliminates the convenience value proposition of a TPM.

Selling passwordless authentication as a solution requiring a PIN just isn't recognizing that the PIN is now the password.

2 comments

You're forgetting the other convenience value of the TPM in Windows, which is that it allows you to use a PIN/bio instead of your (hopefully) long and complex account password.
I think that's a bit of an overstatement. You already enter a password to sign in (or not, if you use biometrics). This is just another password that you enter once at boot. Doesn't seem all that bad of a tradeoff for data security.