Bonum Certa Men Certa

Ubuntu TPM Disk Encryption Requires Snaps



Reprinted with permission from Ryan Farmer.

Ubuntu Plans Really Awful TPM Disk Encryption Which Requires Snaps.



I personally would not depend on this for any sort of a production system.



There’s a short list of reason why I have no confidence in it.



TPMs are incredibly flaky and easy to piss off.



Updating your UEFI firmware can make TPMs refuse to decrypt Bitlocker volumes on Windows.



(Even just changing one setting in the firmware can do it. It got Matthew Garrett, who implemented Microsoft Security Theater Boot on Linux, when he attempted to enable the Third Party Certificate so that Linux could even run on a Lenovo laptop.)



Why would this situation be any different on Linux?



When this happens, say goodbye to all the data on your disk.



I lost an entire Bitlocker volume when I flash updated new Lenovo firmware for this computer. Fortunately, I didn’t have anything important on it and was just updating the firmware as the last thing I did under Windows before removing Windows and installing Linux.



It will require Snaps.



Snaps are an awful package format. They’re an Ubuntu-ism and they’ve been used to spread malware to Ubuntu users through the Snap store.



The Snaps claim to be universal Linux packages, but when I attempted to run GZDoom on Kubuntu, which is just KDE desktop on Ubuntu, it failed and said I had to use GNOME. Very universal, you see. Can’t even deal with a different desktop environment on Ubuntu. I’m sure they work terrifically on other distributions entirely!



Ubuntu does not have a good record at designing things.



Their software and implementations usually end up having all sorts of bugs in them.



Their support for OpenZFS is entirely against both the CDDL and GPL licenses, and relies on an out-of-tree file system module that nobody maintaining the upstream kernel supports or will guarantee won’t break.



So if you enable TPM disk encryption on Ubuntu you will have a flaky TPM-backed encryption atop a flaky illegal out-of-tree kernel module with no upstream support, from “engineers” that have never designed anything else in such a way as to give me any impression that they know what they’re doing.



Your best bet with encryption is to not trust the TPM, or Ubuntu.



You should set it up the officially supported way (LUKS or dm-crypt with a decryption passphrase) and leave the TPM out of it.



(Previously, Ubuntu has offered ecryptfs for /home, but this is not as safe as whole disk encryption, and it also benchmarks worse than encrypting the entire disk.)



You should also do so on an official Linux file system, to further avoid the likelihood of a corrupt file system.



And I would say, don’t even use Ubuntu to begin with.



For a long time, they said the entire system was going to go Snaps instead of Debian packages. That was over a decade ago.



They packaged the GNOME calculator and a few other things as Snaps, and the only thing that did for the users was give them poorly-maintained Snaps from the previous release of GNOME that started up much more slowly and took more resources. (Software bloat.)



Eventually they gave up.



Ubuntu has already had a checkered past packaging GNOME anyway, and has shipped version mismatched “FrankenGNOMEs” with lots of buggy patches.



Now they’re back and claim they’ll do the base system as Snaps and that if they get anything wrong it will screw up your encrypted volume that only the TPM can unlock, if it feels like it.



Also, the TPM is designed not to tell the user how it actually works, so the user can’t know that their disk encryption is safe from backdoors.



This is just yet another, frankly disgusting, thing that Canonical is unleashing, and I think it’s basically another Windows-ism. Bitlocker-style “encryption”.



Recent Techrights' Posts

Unsafe at Any Speed, "Modern" Appliances
Appliances have gotten worse
 
Links 09/09/2026: Airport 'Down' (Glasgow and Edinburgh), 'Open' 'AI' Losses Rise to Pace of 50 Billion Dollars in Losses Per Year
Links for the day
SLAPP Censorship - Part 176 Out of 200: The Sex-Obsessed Non-Experts
We heard some sexual stories
European Patent Office (EPO): No Transparency and No Paper Trail
The incompetence is that of the management, i.e. sheer incompetence of people who never examined a patent in their entire lifetime
Gemini Links 09/09/2026: Going Out, Smartphone Addiction, Mapping the Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 08, 2026
IRC logs for Tuesday, September 08, 2026
Linux is Sabotaged by Botspam and Bloat (de Facto Denial of Service Attack in "Intelligence" Clothing After Rust in "Security" Clothing)
Linux is becoming orphaned, devalued and diluted by GAFAM slop
Switzerland No Longer Wants Microsoft's 'Swiss Cheese' (Back Doors)
Switzerland's patience with Microsoft is wearing thin
Debian is Not a Community, Many Debian Developers Work for Large Companies Including GAFAM (US)
"Community" sounds like friendship and amicability
Links 08/09/2026: Slop Companies Attack Some More Sites, Nvidia Bribes 'Linux' Foundation for Some More Openwashing and for Saying Slop is "Secure"
Links for the day
Gemini Links 08/09/2026: Ultra Introverts, BlackBerry Bold in 2026, and Laughing at LLMs
Links for the day
Microsoft Layoffs in October 2026
Microsoft is a market leader. In NDAs.
Links 08/09/2026: "The Green Revolution Has Failed Africa" and Palantir/Microsoft Harming NHS
Links for the day
Microsoft's Silent Layoffs Are the New Normal at Microsoft
Microsoft has a ton of layoffs all the time, but the media isn't mentioning those as no WARN notices get issued
SLAPP Censorship - Part 175 Out of 200: Implicit and Explicit Coalition Against the UK's SLAPP Industry
SRA recognises the problem
Further Transparency Problems at the EPO
The EPO was never meant to be profitable
Gemini Links 08/09/2026: "Everything Must Go", Announcing Perigee, and Presentations in a Browser
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 07, 2026
IRC logs for Monday, September 07, 2026
Alleged Manager at IBM Says "[t]here are likely to be a lot (and I meant, A LOT) of RAs before December."
"We’re getting pressure from above to put some team members on PIPs."
Links 07/09/2026: Amazon Cargo Plane Crash, .org/.net/.com Domains Considered Risky
Links for the day
Gemini Links 07/09/2026: Cheese, Text-based Life, and Icons in Swaybar
Links for the day
Freedom, Not Fame, is His Goal
pursuit of money can be not only tiring but also involve abandoning one's freedom
Links 07/09/2026: Slop Trashes Memory of Parton, Flock Surveillance Infuriates Everyone
Links for the day
Getting Better After 20 Years
Exactly two months from now this site is turning 20
EPO Hiding Cocainegate and Abandoning Transparency (Even Access to Very Basic Information is Denied)
The EPO isn't just becoming like a private for-profit corporation. It's also becoming more secretive.
Richard Stallman Has Resurrected Lost Updates
We didn't ask about it
SLAPP Censorship - Part 174 Out of 200: Cascading Scandals and a Path Towards Much-Needed, Long-Awaited Reform
Reform the UK's law, not "Reform UK"
EPO's Gema Requena Sempere (PD People) Contacted Regarding Children With Disabilities
In the coming week we may be in fruitful contact with some media regarding EPO scandals
Over at Tux Machines...
GNU/Linux news for the past day
Gemini Links 07/09/2026: Music Composition, Free Stuff, and Self-hosting Git Repos
Links for the day
IRC Proceedings: Sunday, September 06, 2026
IRC logs for Sunday, September 06, 2026