TPM-backed thin-client encryption got bypassed three different ways, then the post argues for UKIs and systemd-cryptenroll.
1 comment
if the fix is moving to uki plus systemd-cryptenroll, does that actually remove the “patch initramfs and dump the key” class of break, or is it still just shifting where the tpm handoff happens?