Hacker News new | ask | show | jobs
by lostmsu 15 hours ago
That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely.

Basically if any bug surfaces in the encryption setup snap permanently loses the ability to update kernel, which, if you care about security, means the system has to be reinstalled to resume receiving kernel bug fixes. The issue is in "Wishlist".

https://bugs.launchpad.net/snapd/+bug/2045417

1 comments

Far better to just use the raw tools and manage it yourself ala arch wiki:

https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...

The problem with manuals like that is they are like commercial flight checklists, except in most cases the user is not a professional pilot.