Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
6jQhWNYh
41 points
19 comments
July 28, 2026
Related Discussions
Found 5 related stories in 315.9ms across 15,236 title embeddings via pgvector HNSW
- TPM-Sniffing LUKS Keys on an Embedded Linux Device [CVE-2026-0714] Tiberium · 19 pts · March 01, 2026 · 57% similar
- Ubuntu wants to strip some of GRUB features in 26.10 for security purposes dryarzeg · 48 pts · March 25, 2026 · 53% similar
- Since Linux 6.9, LUKS suspend stopped wiping disk-encryption keys from memory IngoBlechschmid · 436 pts · July 02, 2026 · 49% similar
- Microsoft is using TPM chips to crack down on pirated Windows activations akyuu · 28 pts · July 27, 2026 · 47% similar
- Linux PTP mainline development war story and new features ahlCVA · 11 pts · April 20, 2026 · 46% similar
Discussion Highlights (5 comments)
lostmsu
That snap-based TPM setup also breaks spectacularly. I would highly recommend people using something else entirely. Basically if any bug surfaces in the encryption setup snap permanently loses the ability to update kernel, which, if you care about security, means the system has to be reinstalled to resume receiving kernel bug fixes. The issue is in "Wishlist". https://bugs.launchpad.net/snapd/+bug/2045417
tryauuum
holy hell! snap-based kernel can someone explain like I'm 5, what's the point of during storing disk encryption keys in TPM? What kind of attack or attacker do we protect from? my logic is following: - if the attacker is remote and somehow modifies my kernel... Yes, the tpm and hardware attestation (is this the term?) would have saved me. But I'm fucked anyway since the attacker already has root on my computer - if the attacker is local -- yes, with tpm they cannot steal just the hard drive and bruteforce it offline. But they can just reset bios and install their own os and trick me into typing the os passwords? Or even if they cannot trick me (hard to spoof my os UI) they can just install a physical keylogger?
voidnullvalue
so, if you use encryption on ubuntu you get a vendor controlled delivery path that has all the practical properties of a backdoor, without the transparency to easily prove its not being used as one
altairprime
Nice to see a Linux vendor developing a sealed environment, but rather cruel of them to hide it silently behind a disk encryption checkbox. I suppose they must consider their non-paying users as test subjects? Lots of bugs in process here that need to be cleaned up for this to remain viable if Steam Linux decides to compete in the sealed-signed-attested space someday.
tomega2134
It seems it's quite often that Ubuntu reminds me how much I appreciate Mint dropping everything snap.