There are some speculations about TPM uncontrollably sending data to manufacturer servers if a laptop has any Internet connection. Others say it’s not intended/capable of that, like this answer for example (which is 5 years old though).

Lemmy, what do you say?

  • marcos@lemmy.world
    link
    fedilink
    arrow-up
    32
    arrow-down
    2
    ·
    1 year ago

    The TPM doesn’t do anything by itself.

    But if Windows is sending all of your data, including stored files and passwords for some third party like its TOS says it can, than that’s Windows breaching your privacy. Or if the remote management hardware that comes with every computer is allowing some third party to access it with more capabilities than even you have, like they are normally designed, than that’s your CPU’s manufacturer breaching your privacy (but those are supposed to be turned off).

    But again, the TPM by itself doesn’t do anything.

    • LWD@lemm.ee
      link
      fedilink
      arrow-up
      5
      arrow-down
      5
      ·
      edit-2
      1 year ago

      Playing devil’s advocate here: what’s the chance TPM is preloaded with garbage that would make Microsoft blush, but the operating system you’re using is Linux with the typical proprietary blobs that you need these days?

      Edit: got rid of an extra confounding variable in my question

      • marcos@lemmy.world
        link
        fedilink
        arrow-up
        17
        arrow-down
        1
        ·
        1 year ago

        You are looking at the wrong place. The TPM is a very standard piece of hardware, that shouldn’t even need firmware (it would completely cancel the entire point of it). It enables a whole lot of shit, but it isn’t the thing that does the shit.

        Now, you can go look at the always-on network enabled uncontrollable management unity that exists inside your computer’s processor… Intel pinky swears they can’t access them in any way and will only activate them if you pay extra¹; AMD AFAIK doesn’t even try to say anything.

        1 - Makes sense to you? Well, how do they activate it if they can’t access it?