BitLocker attack protection against performance. Why Linux turned off TPM encryption by default
Productivity is leading, and safety is optional.
Last year, Linux 6.10 introduced Trusted Platform Module 2.0 bus encryption and communication security. This enhancement was introduced following demonstrations of attacks in which researchers demonstrated the recovery of VitLosker keys and the interception of TRM traffic. Unfortunately, after the merge, the feature was enabled by default only for x86_64, because it was specifically tested there. Now, more than a year later, the behavior has changed. In the mainline kernel branch, this feature is now disabled by default.
The change has already been introduced in the Linux 6.18 kernel and is marked for porting back to the supported branches that started life with 6.10, such as 6.12 LTS and 6.17. It raises a question about the configuration switch TSG_TPM2_HMAS. It does not disappear and remains available to all who need it from NMAS and encryption of transactions in the TRM bus, but it is no longer active by default in kernel compilations for x86_64 architectures.
The reason for this change is simple. The developers agree that the current implementation significantly slows down the system, and the benefits are not yet fully realized until the status of a function that is enabled for everyone without exception. The code with the change is already accepted. This will allow the kernel team to more closely assess the real security benefit and work on optimizations, with the option to include it in a future release if the balance between security and performance is favorable.
For users, this means freedom of choice. For those who want maximum protection for their operating system with TPM 2.0, there is no reason to manually enable TSG_TPM2_NMAS when building the kernel or in the distribution settings. For those who rely on standard builds, the change will reduce system load without sacrificing functionality. The kernel team is keeping the option in the arsenal and continuing to search for a configuration that will provide a tangible security benefit without unnecessary speed loss.
Source: https://www.kaldata.com/