logoalt Hacker News

lostmsutoday at 4:32 PM2 repliesview on HN

That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely.

Basically if any bug surfaces in the encryption setup snap permanently loses the ability to update kernel, which, if you care about security, means the system has to be reinstalled to resume receiving kernel bug fixes. The issue is in "Wishlist".

https://bugs.launchpad.net/snapd/+bug/2045417


Replies

evan_a_atoday at 6:56 PM

Far better to just use the raw tools and manage it yourself ala arch wiki:

https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...

show 1 reply