logoalt Hacker News

rasengantoday at 5:04 AM4 repliesview on HN

> TPM-backed full-disk encryption

This is going to be very useful for servers hosted in third party DCs.


Replies

Davieytoday at 5:51 AM

Keeping the key in the same room as the padlock only protects against casual drive theft and secure disposal.

Personally I'm more worried about someone stealing the entire server or a local threat actor.

Sure, keep TPM to help with boot integrity, maybe even a factor for unlock, but things like Clevis+Tang (or Bitlock Network Unlock for our windows brethren) is essential in my opinion.

djkoolaidetoday at 5:30 AM

The beta installer was completely unsuccessful in setting the TPM-backed disk encryption on both a ThinkPad X1 Carbon (Intel 258V) and a ThinkPad P14s (AMD 300-something). Hopefully they ironed that part out in the release, but it seems still early for this feature (at least for my comfort level).

show 1 reply
Gigachadtoday at 5:59 AM

I want this on my own homeserver. Protection against someone stealing the server without requiring me to type a password every boot.

show 1 reply
senectus1today at 5:37 AM

oh man i hope this works on dell laptops