I don't understand how this is not downvoted into oblivion. As others have already pointed out, this is absolute BS.
I don't understand how this is not downvoted into oblivion. As others have already pointed out, this is absolute BS.
Can a TPM not be used to remotely attest that you are running an unmodified OS and a TPM device that has been approved by the DRM implementer, before handing you an encryption key that never touches the disk?
Can you not restrict the list of approved OS to those that do not allow root/kernel access to the user?
Can you not restrict the list of approved TPMs to those that cannot be "easily" compromised? (i.e. only allow TPMs in the same die as the CPU)
Just because it's not used today does not mean it won't be used tomorrow. Microsoft has not completely pushed this through yet because they know that half of their userbase are pirates. But they are making preparatory steps for it, such as blocking systems without TPM or older CPUs out of Windows 11.
Just look at Android to see what it will look like in a few years.
Riot Games's anti-cheat for Valorant will already not let you play if you don't have a TPM and Secure Boot enabled, and I'm pretty sure you need to have factory (Microsoft) keys for it to work.
Google has recently backtracked on their WEI API proposal which would give websites access to TPM remote attestation, but it will be back once people cool off. Once it's released you can count on every website with ads (like YouTube) to slap it on just to ensure you don't block them.
The list of things you cannot do on your Linux box will just keep increasing over time.