• [object Object]@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      16 days ago

      The TPM takes “measurements” of the system and releases the decryption key only if they’re all correct. Files on the disk are encrypted, so booting into another OS with a bootable media doesn’t work (measurement picks up the fact that you booted into another OS). When the system does boot properly, the Windows lock screen prevents you from viewing the files.