Qemu already supports TPM pass through and secure boot.
Qemu already supports TPM pass through and secure boot.
Backdoors only really became a pressing concern due to ubiquitous Internet access. When I first setup a Windows VM and install whatever application software and updates, its Internet access is through a public VPN only. And it contains no information to tie it back to me.
Before I put any sensitive information on it, I kill its Internet access and never reenable it. So there is no way to exfiltrate data that I care about. Any produced information leaves via a local Samba share.
Leaking fixed identifying information about my hardware, or forming a side channel to a new VM instance would violate this security. I doubt the TPM would store persistent personal application data, but I don't need to be the first one to find out.
Edit: autocorrect TPM
I have not found good docs on what TPM exactly does in Windows 11, but people I trust tell me to distrust it, so I do.
One could conclude that they are requiring TPM so they can eventually turn on BitLocker by default.
> Unlike VMware, which creates a virtual TPM, VirtualBox's new driver will require a host to have a TPM 2.0 processor for this feature to work.