Live data from Hacker News

TPM-backed Full Disk Encryption is coming to Ubuntu

ubuntu.com

51–60 of 71 posts

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#51

Earlier quoted context omitted.

It worked out of the box on my Arch install. I'm running a LUKS volume which holds an LVM with the ext4 fs for the system and the swap. I'm also running TPM + PIN / FIDO2 unlocking. Didn't need to fiddle with anything. The most part of this install was going through the manual process of creating filesystems and whatnot. Bonus points compared to Windows for actually staying asleep instead of randomly waking up while…

>It worked out of the box on my Arch install. Ubuntu isn't Arch I think. Average Joe switching away form Windows isn't gonna start learning Arch. >Bonus points compared to Windows for actually staying asleep instead of randomly waking up while in my bag. That doesn't happen under hibernate. You used sleep thinking it was hibernate, that's why you had that issue.

> That doesn't happen under hibernate. You used sleep thinking it was hibernate, that's why you had that issue.

I mean, while asleep, the PC blinks its annoying light every second. While hibernating, it doesn't. I'm pretty sure there were no blinky lights, they would have prevented me from falling asleep. It's why I went out of my way to enable hibernating.

Also, see the other posts around the thread. There are absolutely ways to wake up a PC from hibernation. Even from full shutdown.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#52

That's groovy baby, but can anyone give me the technicals on why we can't have Hibernate(not sleep) out of the box on Ubuntu like we can on Windows? That was one of the deal-breakers for me making the switch. If I understood it correctly, it's because of Z-RAM and if I'm also correct, full disk encryption is another roadblock in the path of the hibernate feature.

So hibernate is somewhat unreliable and prone to data loss, image you hibernate after having installed a new kernel, so the decision was made to disable it due to that IIRC, independent of secure boot. With secure boot and lockdown, hibernate is no longer possible on an alternative reason: We need to ensure that the kernel memory has not been tampered with. If you hibernate, you could then go and modify the memory in…

From my (shallow) understanding you can encrypt the swap using dm-crypt/LUKS as well and unlock using TPM. It's supported using systemd-cryptenroll on Arch.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#53

Earlier quoted context omitted.

That very much depends on your definition of "works". Does the machine go through the steps to save memory to disk and enter a low power state? Yes. But then windows can and does decide to wake itself up at any time, resulting in physical damage to the machine if it's stored in a closed bag. Discharging the battery and heating up the entire machine dramatically reduces your battery's lifetime. You cannot disable this…

>So yes, it 'works', with the caveat that the machine may wake itself at any time, burn through the entire battery and possibly do irreprable damage to your machine. You haven't read my comment fully or are confusing hibernate with sleep. I was talking about hibernate which 100% works, not sleep. Hibernate can't wake up your laptop as your machine is completely powered off.

I have had windows wake itself up after I clicked the “hibernate” button in the start menu. It’s pretty infuriating.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#54
post #6
post #3

Earlier quoted context omitted.

> but those have a downside of the TPM needing to be updated with every new kernel. This depends on the configuration. If you don't bind the key to PCRs at key creation time kernel updates don't affect the workflow and you still will take advantage of other TPM features such as locking the key after several unsuccessful attempts. Take a look at the systemd configuration: https://www.freedesktop.org/software/systemd/m…

IMHO the PCRs are way too much trouble and defend against attacks that are rare outside of extremely spooky circles. They were the biggest problem with Bitlocker too.

PCRs being problematic was actually one of the issues policy mechanism in TPM 2.0 was meant to resolve (see "Non-Brittle PCRs (New in 2.0)" in [0]).

Tldr version is that you'd authorize OS manufacturer's kernel signing key to use the TPM key so that each time your OS vendor signs the kernel it's OK for the TPM.

Sadly I don't think I've seen this deployed in the wild.

[0]: https://ebrary.net/24725/computer_science/quick_loading

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#55

Earlier quoted context omitted.

So hibernate is somewhat unreliable and prone to data loss, image you hibernate after having installed a new kernel, so the decision was made to disable it due to that IIRC, independent of secure boot. With secure boot and lockdown, hibernate is no longer possible on an alternative reason: We need to ensure that the kernel memory has not been tampered with. If you hibernate, you could then go and modify the memory in…

Thanks for the explanation. That kind of sucks though. I was spoiled by how good hibernate works on Windows and assumed any modern desktop OS should come with this feature if it wishes to "cut the king". I guess it's another nail in the "switching to Linux" coffin.

There's also the issue of hibernating a 32Gb image to a 512Gb ssd several times a day. That can't be good for longevity.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#56
post #8

That's groovy baby, but can anyone give me the technicals on why we can't have Hibernate(not sleep) out of the box on Ubuntu like we can on Windows? That was one of the deal-breakers for me making the switch. If I understood it correctly, it's because of Z-RAM and if I'm also correct, full disk encryption is another roadblock in the path of the hibernate feature.

Windows these days prefers what they call modern standby and you probably don't want it. I have a ThinkPad and this is what it's like: Close the lid and stuff laptop into my backpack. I travel to work and when I pull my machine out of my bag, it has 12% battery left, is super hot, and the fan is screaming like the machine is trying to fly away. All because Microsoft thinks PCs should be more like iPhones.

It might be broken on your laptop, but it does not seem to be broken in general.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#57

Earlier quoted context omitted.

Thanks for the explanation. That kind of sucks though. I was spoiled by how good hibernate works on Windows and assumed any modern desktop OS should come with this feature if it wishes to "cut the king". I guess it's another nail in the "switching to Linux" coffin.

There's also the issue of hibernating a 32Gb image to a 512Gb ssd several times a day. That can't be good for longevity.

>hibernating a 32Gb image to a 512Gb ssd several times a day

1) It's 16GB image to 1TB SSD for me, but who needs to hibernate several times a day? I only use it when I take my laptop out of the house on long journeys which is a couple of times a month at most.

2) It's my SSD, I paid for it, and I should be allowed to use it how I please, even like in your example of hibernating it several times a day if I wish. Why should the OS dev stop me from doing this? It's my HW, not theirs.

I would understand this angle if he OS developer(Canonical) was also responsible for the longevity and the warranty of the HW I bought from them, the way Apple and sometimes Microsoft is, but since for Canonical this is not the case since they don't sell laptops, why should they limit me like that? You can show a disclaimer telling the user that hibernate will degrade the SSD if that's a big legal issue for them.

Heck, even Microsoft let's you enable hibernate with just 3 clicks.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#58
post #30
post #12

Earlier quoted context omitted.

Looks perfectly aligned with corporate and especially government IT practices. There the user is by far not the owner.

So if Ubuntu is pivoting hard into big corporate/govt Who’s the new big community desktop distro?

Linux Mint of course

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#59

Earlier quoted context omitted.

That very much depends on your definition of "works". Does the machine go through the steps to save memory to disk and enter a low power state? Yes. But then windows can and does decide to wake itself up at any time, resulting in physical damage to the machine if it's stored in a closed bag. Discharging the battery and heating up the entire machine dramatically reduces your battery's lifetime. You cannot disable this…

>So yes, it 'works', with the caveat that the machine may wake itself at any time, burn through the entire battery and possibly do irreprable damage to your machine. You haven't read my comment fully or are confusing hibernate with sleep. I was talking about hibernate which 100% works, not sleep. Hibernate can't wake up your laptop as your machine is completely powered off.

Is that the case anymore with a battery and Intel ME? I don’t believe it is.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#60

Earlier quoted context omitted.

Meanwhile my mom just asked me to switch her Dell to her favorite linux mint flavour and the key enrollment was literally 3 key presses plus the password away.

Oops, I tried to install the nvidia drivers, but it doesn't seem to have worked. I got a weird screen during the process, pretty sure it was blue, and the default option was 'continue boot' which I selected, I think maybe it was the 'BIOS' ? I couldn't google what to do while at that screen, or screenshot it either, for some reason. I've tried uninstalling then reinstalling the drivers, but that hasn't made the myste…

Most laptops don't have nvidia cards. And none of those issues you're talking about occurred. She's been a happy linux mint user for more than 5 years. I was just trying to get her off her old ultramobile celeron laptop and she refused to use the new one until I ran the mint installer. For me the biggest challenge was figuring out whether to install the Mate or Cinnamon version.

It asked me for an 8 character password during install, rebooted, i entered enroll existing key. I entered the password and then continued the install, that was it. Runs like a charm, boots like a charm.

She's over 70 and she absolutely loathes the random software that various windows things try to install, or the antivirus sneaks in with the next update and stuff like that.

She just browses the web, streams stuff and wants to make sure she can screencapture the streams she watches. Turns out for that use case Thunderbird is also quite good and to my surprise the google 2FA oauth phone login makes it really easy for her to log in to google. I still remember the times when I would have to reset her google password for her.

Not to dismiss your experience, but I think for a lot of basic users it works really well.

Post reply on HN