logoalt Hacker News

tryauuumyesterday at 9:35 PM1 replyview on HN

no, I mean the attacker boots his own copy of Windows or Ubuntu, which is supposedly trusted by the UEFI keys. Will tpm somehow detect that it shouldn't unlock secrets for this boot?


Replies

noisem4keryesterday at 10:41 PM

Yes. The PCR state after booting won't match that of the regular system, so the TPM will refuse to give up the key.