Earlier quoted context omitted.
> That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. True, any preboot password method (even fully software) will be sufficient to preve…
No one wants a preboot password though. TPM means the system can boot and then do face login or whatever using the user's password in exactly one place. This is as much as most users will tolerate. And it also means Microsoft account recovery can work to unlock a forgotten password. The whole point is Microsoft don't want user devices to ever be trivially bypassed, regardless of how unlikely that is (probably more li…
In fact in many cases a preboot password is safer. Because the comms between the TPM and the OS can often be sniffed. And if the TPM doesn't need validation because it hands off its keys, it can be bypassed that way.
Again not really something that consumers have to worry about, but it's not quite difficult anymore to pull this off.