this post was submitted on 17 Sep 2025
560 points (99.1% liked)

Technology

75258 readers
3690 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Should OS makers, like Microsoft, be legally required to provide 15 years of security updates?

you are viewing a single comment's thread
view the rest of the comments
[โ€“] Buddahriffic@lemmy.world 2 points 7 hours ago (1 children)

TPM is more about securing data from PC owners rather than for them. Since it's there anyways, it is used to support bitlocker, but the reason they are pushing it so much is because it might (depending on whether it actually is secure) be able to allow content providers to allow users to view their content without needing to give them access to copy or edit it.

And there isn't any guarantee that the uses that do benefit the user's security don't have some backdoor for approved crackers to get in. Like doesn't the MS account store a copy of the recovery key for bitlocker? Which is nice for when the user needs it, but also comes in handy if MS wants to grant access to anyone else.

[โ€“] Smith6612@lemmy.world 1 points 1 hour ago

Microsoft does on Home Edition without even asking, and it doesn't provide the users with a choice to store the key locally OR put it on the Cloud account, like Windows Pro does. I'm sure Microsoft has a master key to an account as well. But one can hope they do not, and they are also storing those BitLocker keys in an encrypted fashion in whatever database runs the backend.

Also agree with you on TPMs. They are useful when invoked by the user. DRM on content and software is, and always will be, anti-consumer. As for now secure TPMs are, I know Infineon did have that Random Number Generator bug which basically broke the TPMs. So there's that.