BennyCHill [he/him]

Goblin of liberal democracy

  • 0 Posts
  • 2 Comments
Joined 1Y ago
cake
Cake day: Jul 12, 2024

help-circle
rss

both intel and amd have introduced memory encryption a couple gens. ago although not supported on all devices.


TPM uses parts of your system like hardware configuration, bios version, can even use parts of the OS, to generate a hashcode to decrypt your drive, so if anything gets replaced it wont automatically decrypt. what this allows is to have a much more complex decryption key and allows you to rely on OS security and much simpler passwords to protect your data because your OS (which cannot be replaced without breaking TPM) will protect against brute force attacks with retry delays and limits.