Live data from Hacker News

TPM-backed Full Disk Encryption is coming to Ubuntu

ubuntu.com

61–70 of 71 posts

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#61
post #47
post #30

Earlier quoted context omitted.

So if Ubuntu is pivoting hard into big corporate/govt Who’s the new big community desktop distro?

The transition from Ubuntu to Debian is about as simple as it gets, since Ubuntu derives much of their base from Debian..

As someone said, "Ubuntu is Debian-based like milk is grass-based" :)

But certainly the bulk of the tools must be familiar.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#62

Earlier quoted context omitted.

Windows can wake itself from hibernate. Killing all of the wake timers and editing specific keys in the registry will usually fix this, but it's messy and not something typical users are comfortable doing.

This. During lockdowns, I dusted off an old PC and set it up with windows for gaming. The computer was in front of my bed. One out of two nights, the thing would randomly wake out of hibernation, blasting the freaking blue bitlocker screen at me (password unlock, since that PC didn't have a tpm). This PC was kept reasonably up to date, too (usually installed whatever update at the most a day or two after they came ou…

Right, I have the same problem with my PC, guess I'll look for those hacks.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#63
post #39
post #30

Earlier quoted context omitted.

So if Ubuntu is pivoting hard into big corporate/govt Who’s the new big community desktop distro?

No idea! Debian proper? Fedora? Nix? Arch?.. (I personally run a relatively niche distro, https://voidlinux.org/ )

Void's great although definitely for the tinker crowd (like arch was), debian seems like the better community choice

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#64
post #12
post #5

> the bootloader (shim and GRUB) and kernel assets will be delivered as snap packages (via gadget and kernel snaps), as opposed to being delivered as Debian packages. And there it is. I suppose having your kernel command line signed by Canonical and unmodifiable by the system owner without a pain-in-the-ass manual 'machine owner key enrolment' process is very much on-brand for Snap.

Looks perfectly aligned with corporate and especially government IT practices. There the user is by far not the owner.

But even in those environments, Canonical isn't the owner.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#65
post #32

Earlier quoted context omitted.

On Ubuntu you do have this option, you just have to set it up yourself. They don't prioritize support for it because "people who want to hibernate a laptop" is a rounding error in their customer population statistics.

>On Ubuntu you do have this option, you just have to set it up yourself. Which means it's not available. Technically my car can also go diving underwater, you just have to set it up yourself for that. I expect stuff on my OS to work out of the box, not require hours of dangerous tinkering with the risk of braking, to get something basic to work. >They don't prioritize support for it because "people who want to hibern…

Sounds like Ubuntu is not for you, then. For different reasons, it's not for me either. Good thing you've got Windows.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#68
post #31

Earlier quoted context omitted.

No, he's right. Windows can wake the computer from total shut down even (S5). It uses RTC alarms: https://en.wikipedia.org/wiki/Real-time_clock_alarm

"Can be set to wake up" doesn't mean "will wake up".

Modern versions wake up out of the box, you need to tinker with them to stop that.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#69

Earlier quoted context omitted.

That very much depends on your definition of "works". Does the machine go through the steps to save memory to disk and enter a low power state? Yes. But then windows can and does decide to wake itself up at any time, resulting in physical damage to the machine if it's stored in a closed bag. Discharging the battery and heating up the entire machine dramatically reduces your battery's lifetime. You cannot disable this…

>So yes, it 'works', with the caveat that the machine may wake itself at any time, burn through the entire battery and possibly do irreprable damage to your machine. You haven't read my comment fully or are confusing hibernate with sleep. I was talking about hibernate which 100% works, not sleep. Hibernate can't wake up your laptop as your machine is completely powered off.

> Hibernate can't wake up your laptop as your machine is completely powered off.

That is quite simply not true.

Re: TPM-backed Full Disk Encryption is coming to Ubuntu

#70
post #35

Earlier quoted context omitted.

Well shit, we were just joking the other day on mastodon about the kernel being distributed as a snap. I guess this is it, then. I'm tired of computers being awful :(

Just don't use Ubuntu, there are plenty of fish in the sea :-)

Yeah, I completely switched to Arch after I got the ads in my apt-get commands. It's a bit more annoying and unstable, but overall a much better experience than Ubuntu.

I still have a few server instances on Ubuntu, but I'm moving them to straight Debian or arch when they need major upgrades.

Post reply on HN