Remix.run Logo
lostmsu 2 days ago

That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely.

Basically if any bug surfaces in the encryption setup snap permanently loses the ability to update kernel, which, if you care about security, means the system has to be reinstalled to resume receiving kernel bug fixes. The issue is in "Wishlist".

https://bugs.launchpad.net/snapd/+bug/2045417

evan_a_a 2 days ago | parent | next [-]

Far better to just use the raw tools and manage it yourself ala arch wiki:

https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...

lostmsu 2 days ago | parent [-]

The problem with manuals like that is they are like commercial flight checklists, except in most cases the user is not a professional pilot.

sneakerblack a day ago | parent [-]

Skill issue

Jokes aside, I agree on the sense that this should be a solved problem. On the other hand, if the only implementation is a broken one, there's only one way to help yourself, and that is learning how to do it and helping yourself

2 days ago | parent | prev [-]
[deleted]