Forgot your password?
typodupeerror

Comment Re:it's all about trust (Score 1) 87

Why are you trusting anything?

That's what TPM is fundamentally about. You talked in another post about it being for separation, that's a trust function, so clearly you know it's about trust. That shows that this comment begins disingenuously.

Open Source TPM software and hardware exist, and are under the user's control in a way that any other TPM is not. Not every motherboard has a TPM slot, but boards with them are not hard to come by, so it is feasible for users to have a TPM that they actually do control. Neither the TPM in your CPU nor the average add-in TPM is actually that. Being able to remove things from it is not the same thing as being in control of it, although it's a part of being in control.

Comment Re:TPM Suspicion Intensifies (Score 1) 86

Windows provides 3 distinct ways to clear all TPM data. Your UEFI provides ways to clear TPM data. It is under *YOUR* control.

The "He who can destroy a thing controls it" idea from Dune was about political control, not direct and literal. You can destroy that data at any time, but that's the extent of your control over it. That's not nothing, but it's far from the hardware working for you.

The fact that a root user can't access information al-a-carte is foundational to the feature

Right, that's why the feature is not for my benefit. If I want to bypass security between applications which is not for my benefit (for example to prevent me from copying data that I'm actually intending to copy) and I can't do that because TPM says no, that's working against me.

Having a separate secure enclave is a good idea, having it be so secure that I can't do what I want with it when I want to is a bad one. Most users won't even try, you only need to make it so that they can't trivially be tricked into it. A big warning, a short delay, a hoop to jump through so that a person who can't read the warning can't get there.

Comment Re:Interesting (Score 1) 26

the people who are actually in the business of data centers, AI, and space, think it can be done and can be cost effective

That's what they say.

Do you believe everything people say?

If it turns out that they can do it

They can't, and only people who know how nothing whatsoever works thinks they can.

Comment Re:kids these days ... (Score 1) 87

A like for like CPU change would trigger a windows reactivation, and that was before you even learned to spell TPU.

Not IME. I changed the CPU on this system that I'm using right now back when it still had Windows on it without requiring reactivation. It took changing the motherboard to have to reactivate.

Comment Re:Constructive responses anyone? (Score 1) 59

Teams works?

Seriously, Teams is one of the worst bits of software I have ever used. It seems like it was designed to be unspeakably awful in every way. It's quite remarkable that they made it quite so shitty.

I haven't used Element, but I'd be surprised if it was somehow worse. Teams is like the absolute zero of usability, I don't think you can go lower than that without breaking the laws of physics.

Comment Re:kids these days ... (Score 1) 86

TPM 2.0 includes rate limiting, and in most cases now it is actually an fTPM built into the CPU which is even more secure. This 45 minute brute force attack doesn't work.

Secureboot is not a sandbox. It is a certificate chain that validates that the OS bootloader, kernel, and basic drivers have not been tampered with. Malware used to replace the NTFS drive in Windows so that anti-virus software couldn't delete its files, and it effectively sandboxed the whole OS by controlling what it could see on the disk. That became impossible once Secure Boot was enabled, because the NTFS driver had to be signed with the Microsoft key.

If you care about security, you can use the same measure to make sure your Linux OS hasn't been tampered with. You can load your own key and sign your own kernel too, it's a mandatory requirement of Secure Boot.

Comment Re:If they are thermally efficient enough (Score 1) 26

The problem on Earth is mostly NIMBYs, and also a bit the time it takes to set up new electricity supplies.

It looks like the cost to orbit is going to decrease substantially, and solar up there can cover all the power needs 24/7, and so far Space NIMBYs have not had much effect on those mega constellations.

Slashdot Top Deals

Staff meeting in the conference room in 3 minutes.

Working...