logoalt Hacker News

Graziano_Mtoday at 7:18 PM0 repliesview on HN

With TPM backed keys the point is that the user doesn’t know the decryption key, and he doesn’t need to enter it to boot. There can be a backup/recovery key, but being prompted for it should set off alarm bells.