hn • r/hackernews
Comment on: Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
Where the TPM helps is preventing the attacker from establishing low level (kernel, bootloader, or firmware) persistence, since modifications of these components would change the TPM PCR measurements and result in a boot