Just upgrading your firmware with bitlocker enabled can brick your PC.
Just upgrading your firmware with bitlocker enabled can brick your PC.
Nobody says "disable disk encryption right away incase the tom forgets the keys". The vast majority of TPM's manage to not forget the keys.
The reason it's done this way is to allow multiple methods of accessing the disk, to allow the encryption password to be changed without having to rewrite every single sector of the disk, etc, etc. You can even “erase” the disk in one swift operation by simply erasing all copies of the key.
How many home users have that? How many stories of personal data loss are we going to hear as windows 11 ready PCs start to die?
https://boingboing.net/2026/01/05/everyone-hates-onedrive-mi...
Windows also bit me in the ass with this feature, but tailscale not enabling encryption wouldn't have helped one iota.
Could you elaborate ? Firmware/OS should not affect TPM contents ? Otherwise e.g. TPM-reliant Windows installs would break ?
In addition there are cloud scenarios where your VM has a TPM and you want to e.g .stop a malicious actor poaching your VM and running it elsewhere.
Having the tailscale TPM tied to your cloud hypervisor prevents the "lift and shift" attack.
https://www.reddit.com/r/MSI_Gaming/comments/15w8wgj/psa_tpm...
https://learn.microsoft.com/en-us/windows/security/hardware-...
The correct procedure is to unlock the keys, copy them out of the TPM, perform the upgrade, reboot to remeasure the system state, then finally store the keys back into the TPM.