news.ycombinator.com• Jun 14, 2026• 1 min read
Ask HN: How can you trust your hardware?There's a widespread idea in the technical community that TPMs don't provide any security:- https://news.ycombinator.com/item?id=37435450- https://learn.omacom.io/2/the-omarchy-manual/50/getting-started?search=tpm#getting-started (see advice on tpm)- NSA encourages we use it https://media.defense.gov/2024/Nov/06/2003579882/-1/-1/0/CSI-TPM-USE-CASES.PDFBut, TPMs have real use cases: - It theoretically prevents kernel level exploits extracting secrets.- Projects like Qubes suggest using it to prevent evil maid attacks: https://doc.qubes-os.org/en/latest/user/hardware/system-requirements.html#recommendedBUT...- It provides a weak level of device attestation from the manufacturer: https://blog.cloudflare.com/anchoring-trust-a-hardware-secure-boot-story/#uefi-attacks- That cloudflare article suggests using AMD PSP which is equivalent to Intel ME that the NSA is know to request the disabling of https://stateofsurveillance.org/articles/technical/intel-management-engine-deep-dive/So it seems l