Linux Now Disabling TPM Bus Encryption By Default For Performance Reasons
phoronix.com·7h

LINUX SECURITY

Introduced last year in Linux 6.10 was TPM bus encryption and integration protection for Trusted Platform Module 2 (TPM2) handling. The intent was on better TPM security after a prior security demonstration showed TPM key recovery from Microsoft Windows BitLocker as well as TPM sniffing attacks. Shortly after being merged it was limited to just an x86_64 default where it had been tested the most at the time. Now more than one year later, this feature is being disabled by default in the mainline Linux kernel.

Merged today for Linux 6.18 and marked for back-porting to Linux 6.10+…

Similar Posts

Loading similar posts...