Microsoft say that the main features of TPMs are that they [1]:
> Generate, store, and limit the use of cryptographic keys.
> Use TPM technology for platform device authentication by using the TPM’s unique RSA key, which is burned into itself.
> Help ensure platform integrity by taking and storing security measurements.
One can, in principle, imagine situations á la Apple's T2 chip whereby this could be very useful to the end user -- for example, in hardware rate-limiting whole drive encryption decryption requests. Microsoft don't actually state this as a potential use-case. They go for the rather more prosaic
> Antimalware software can use the boot measurements of the operating system start state to prove the integrity of a computer running Windows 10 or Windows Server 2016. These measurements include the launch of Hyper-V to test that datacenters using virtualization are not running untrusted hypervisors. With BitLocker Network Unlock, IT administrators can push an update without concerns that a computer is waiting for PIN entry.
The rest of the page then goes on about hardware attestation. In reality, I am increasingly convinced that this is all an elaborate DRM scheme, similar to what they integrated in the XBox, with its on-chip crypto. I think we will see increasingly user-hostile, but more "transparent" DRM schemes based around this idea, and continue the cat-and-mouse game of "you are running this code in a VM and that is unauthorised for $MONEY_REASONS".
I'll stick to Linux, thanks.
[1] https://docs.microsoft.com/en-us/windows/security/informatio...
I suspect for most consumer and small-business users, the risk of "a power surge blew out my motherboard and TPM, but I can take the surviving SSD and plunk it in a new PC and salvage my data" is a much more important use case than "someone might steal my PC and get at my valuable unencrypted data." I know we've heard people screaming about this on the MacOS side, but thereit's intertwined with the unrecoverability of a soldered storage subsystem.
Large and technical organizations who might need the encryption are hopefully more likely to have IT staff and policies for backups and recovery, so they'll be able to handle that emergency better.
The data wasn't that valuable otherwise I'd have had it backed up. The problem is it's my game PC. I don't want to constantly backup and sync all my game files as I can easily re-download them anyway and they take a ton of space. The savegames I do want backed up ideally but they're all over the filesystem. So, I recovered some that way. It was educational too, trying to scrape stuff off a broken NTFS image.
But I certainly don't need or want my desktop PC encrypted. I only use my Windows box for gaming and I don't want to waste performance on it.
I assume law enforcement can request those keys from Microsoft if they're backed up to the account.
I would guess extracting the keys from the tpm in other ways is not impossible, but probably sufficiently hard to be not worth it in most situations.
is this for real...?
Since the account was a local account, not one signed into a Microsoft account, the Bitlocker keys were not backed up an all data was lost. I was stunned, I've been doing laptop repair for almost 10 years and I've never seen something this stupid.
It's also designed to not be able to be able to extract the key material out of it.
[0] https://news.ycombinator.com/item?id=27655320
[1] https://news.ycombinator.com/item?id=27656144
Can someone on the inside confirm that my using a new chip won't make me unable to boot into my Windows 11 install "Sorry you need your double secret trusted components to use them with our TPM modules, and thus your* software install."
* "Your" meaning ours, licensed to you until we decide to change the license.
Then, in the case of full drive encryption, you'll be asked for the BitLocker recovery key at bootup.
If you used Windows Hello for authentication, that option wouldn't be available - making you have to use your password instead to login.
If the device can boot without a password or PIN, there are some surprising ways to get into it just by switching networks (if network drives are mounted it will sometimes send NTLM hashes), or by good old brute-forcing.
[1] https://blog.kaniski.eu/2020/12/utilman-exe-to-cmd-exe-and-b...