TPM 2.0 - Is my system safe?

I’ve been using Zorin 17.3 for nine months, dual boot (both on the main drive) with Win 11 (which I never use). I have heard that the TPM 2.0 has been known to destroy a Linux partition. I booted into BIOS to disable the TPM 2.0, but was unable to disable it by itself as it’s nested in a list with other features on the Security page. Is my system safe if I never boot into Windows 11, or am I in danger of having MS sabotage my system? (Once I’ve upgraded to OS 18 and have everything backed up, I’m planning to use GParted to reformat the Win partitions once I figure out which ones are safe to reformat, move them, and combine them with adjacent ext4 partitions). I imagine I’ll need to provide more information in order to get an answer, but thought I’d toss this out as is. Thanks in advance for your input!

If you never boot into Windows OS, yes.
TPM cannot operate entirely on its own.

In some settings, a user must first disable ftpm or ptt, in order to disable TPM.

Can You maybe post some Pictures of Your BIOS with the Options? So, we could take a Look at it.

Thanks for the response. I'll get the screenshot posted tomorrow.

Thanks for the response and the reassurance!

I am not sure about destroying as such. The issue arises like me if I wanted to boot into GNU/Linux OS if the MOK key hasn't been enrolled which can be achieved by using Ventoy. In my case I should have used GPT partitioning instead of mbr. It is possible to resolve this issue using some BIOS-GRUB workaround but can potentially lead to data loss.

In my BIOS I have two TPM options, 'firmware' which uses the BIOS TPM, or 'discrete' (TPM 2.0 module attached to the motherboard). I purchased one so that I could practice enrolling MOK key if I had a client who still wanted to dual-boot, but I don't promote it.

One of the issues to be aware is not to write files directly to the same partition where Windows resides from the GNU/Linux side, you need a separate NTFS data partition if you wanted both OS's to have dual access.

Where data loss has been seen to occur on SSD's is when a user was backing up large Gb's of Data.

Thanks for the reply. I kept Win 11 when I installed Zorin 17.3, nine months ago because I thought I might need Win for a future work assignment. That turned out not to be true and I'm planning to get rid of Win 11 by reformatting the Win partitions and combining them with the ext4 partitions, using GParted, after I upgrade to OS 18 and back everything up. I was concerned about safety in the interim.

1 Like

One of the positives during lockdown for me was being able to use GNU/Linux for 98% for work requirements and using SoftMaker Office for Linux for all Office files. I could even login to the school's shared server with one login using Remmina, whereas Edge in a VM of Windows required 3 logins.

The 2% fail was related to two things:
BrailleBlaster, a free Braille Trabslation software did not work when I migrated from Feren OS to Devuan.
The other was a shared work email address box, but I did get my personal work Outlook365 account setup in Evolution.

Here is the photo. Sorry for the quality, it was the best I could do. The computer is a Powerspec G434, which I believe is a 2019 or 2020 model. Here is a photo of the UEFI. Whether the Intel PTT is enabled or disabled, in either case the setting is "Use discreet TPM Module". I've already been assured that if I don't boot into Win 11 (which I never do), then the TPM won't cause any mischief and it's a white-knuckle experience to go poking around in the UEFI and change settings.

on my system i have TPM 2 enabled along with secure boot which has the updated secure boot 2023 certs and have had no problems with Zorin 18 installing/booting or running.

i dont dual boot with Windows but i do have Windows 11 25H2 running in Gnome Boxes.

i can only state from my own personal experience.
best of luck Steve ..
edit for spelling.

OK, some clarity of wording, a duel is 10 paces at dawn with pistols at the ready, two things are 'dual'. :wink:

The Intel PTT will be a BIOS 'firmware' version of TPM, in much the same way my ASUS BIOS got an update for TPM as a firmware option. 'Discrete' means you have a TPM 2.0 chip installed. On Desktop motherboards from 2019 like my ASUS PRIME X470-PRO, the TPM 2.0 chip was never shipped but they usually came with a TPM 2.0 slot on the motherboard.

What I have found from my experience is having installe PCLOS Debian after cloning failing Windows 10 drive, that I can only make PCLOS Debian boot first by re-arranging the boot order, which then sticks (PCLOS Debian) boots first. If I use Windows Boot Manager, choosing Windows from GRUB, then on reboot I have to revert back to entering the BIOS to make PCLOS Debian the first boot drive.

Q4OS is a different story. It does not show up in ASUS EZmode, it only shows up in the Advanced mode of the BIOS as being present and have to go into the BIOS each time I boot the hot-swap bay drive that has Q4OS.

Pistols? A gentleman uses a sword.

1 Like

you bring your sword i will bring my old trusty FN 7.62 SLR. :slight_smile:
best of luck Steve ..

1 Like

When You System works without Issues, You can let the Settings like they are if don't want to risk soemthing with changing BIOS Settings. But You should at least keep it in Mind for the Future.

1 Like

I propose mudballs at 20 paces sir.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.