Bonum Certa Men Certa

Ubuntu TPM Disk Encryption Requires Snaps



Reprinted with permission from Ryan Farmer.

Ubuntu Plans Really Awful TPM Disk Encryption Which Requires Snaps.



I personally would not depend on this for any sort of a production system.



There’s a short list of reason why I have no confidence in it.



TPMs are incredibly flaky and easy to piss off.



Updating your UEFI firmware can make TPMs refuse to decrypt Bitlocker volumes on Windows.



(Even just changing one setting in the firmware can do it. It got Matthew Garrett, who implemented Microsoft Security Theater Boot on Linux, when he attempted to enable the Third Party Certificate so that Linux could even run on a Lenovo laptop.)



Why would this situation be any different on Linux?



When this happens, say goodbye to all the data on your disk.



I lost an entire Bitlocker volume when I flash updated new Lenovo firmware for this computer. Fortunately, I didn’t have anything important on it and was just updating the firmware as the last thing I did under Windows before removing Windows and installing Linux.



It will require Snaps.



Snaps are an awful package format. They’re an Ubuntu-ism and they’ve been used to spread malware to Ubuntu users through the Snap store.



The Snaps claim to be universal Linux packages, but when I attempted to run GZDoom on Kubuntu, which is just KDE desktop on Ubuntu, it failed and said I had to use GNOME. Very universal, you see. Can’t even deal with a different desktop environment on Ubuntu. I’m sure they work terrifically on other distributions entirely!



Ubuntu does not have a good record at designing things.



Their software and implementations usually end up having all sorts of bugs in them.



Their support for OpenZFS is entirely against both the CDDL and GPL licenses, and relies on an out-of-tree file system module that nobody maintaining the upstream kernel supports or will guarantee won’t break.



So if you enable TPM disk encryption on Ubuntu you will have a flaky TPM-backed encryption atop a flaky illegal out-of-tree kernel module with no upstream support, from “engineers” that have never designed anything else in such a way as to give me any impression that they know what they’re doing.



Your best bet with encryption is to not trust the TPM, or Ubuntu.



You should set it up the officially supported way (LUKS or dm-crypt with a decryption passphrase) and leave the TPM out of it.



(Previously, Ubuntu has offered ecryptfs for /home, but this is not as safe as whole disk encryption, and it also benchmarks worse than encrypting the entire disk.)



You should also do so on an official Linux file system, to further avoid the likelihood of a corrupt file system.



And I would say, don’t even use Ubuntu to begin with.



For a long time, they said the entire system was going to go Snaps instead of Debian packages. That was over a decade ago.



They packaged the GNOME calculator and a few other things as Snaps, and the only thing that did for the users was give them poorly-maintained Snaps from the previous release of GNOME that started up much more slowly and took more resources. (Software bloat.)



Eventually they gave up.



Ubuntu has already had a checkered past packaging GNOME anyway, and has shipped version mismatched “FrankenGNOMEs” with lots of buggy patches.



Now they’re back and claim they’ll do the base system as Snaps and that if they get anything wrong it will screw up your encrypted volume that only the TPM can unlock, if it feels like it.



Also, the TPM is designed not to tell the user how it actually works, so the user can’t know that their disk encryption is safe from backdoors.



This is just yet another, frankly disgusting, thing that Canonical is unleashing, and I think it’s basically another Windows-ism. Bitlocker-style “encryption”.



Recent Techrights' Posts

Salaries Are Counted in Money, Not in Participation in the Employer's Scheme
articles greatly exaggerating GAFAM salaries
Even Linux Cannot Cope With Slop
Bots on the Web are truly obnoxious
GNU/Linux Has Become More Mainstream in the United Kingdom
It's a long weekend here and we guess some people dabble in GNU/Linux migrations, at least at home
 
Anniversaries Next Month
The month should be otherwise quiet and uneventful for us
Coding is Not Obsolete
we drown ourselves in chaff to meet "LOC" objectives while ignoring everything else
Microsoft Layoffs Perpetual But Silent, People Pushed Out Using Pressure or Incentive Schemes
Earlier this month we named some of the programs
Links 30/08/2026: Apple Rant and LLM (Slop) Scrapers Target Gemini Protocol and Gopher
Links for the day
Walls in Free Software
mind your own business and move on
What a Summer!
Tomorrow is the last day of this month
Links 30/08/2026: Soldiers in Niger Attack Presidential Palace and Airport, Nepali City Struggles to Handle the Many Dead Bodies
Links for the day
Clownflare Sees GNU/Linux Rising to 11% This Past Week
Is it the year of "Linux in China"?
Links 30/08/2026: Russian Strike on a Ukrainian Warehouse and Rhetoric Escalations
Links for the day
Gemini Links 30/08/2026: Photography, Paper Books, Linux Kernel and the Debian Projects Permitting Slop Plagiarism
Links for the day
Imagine a World Where Nobody Fights for Software (and Computing) Freedom
The community keeps fighting back, so some of these ambitions are delayed or watered down
FSF Has Grown (More Staff) After a Year of Financial Growth
On October 4 the FSF turns 41
SLAPP Censorship - Part 166 Out of 200: Garrett Wasn't Found Innocent Per Se, the Court Wanted More Evidence of Who Was Behind Particular Accounts Using Tor
It's complicated
Criminals Don't Obey Laws, California Does Not Enhance Online Safety
It has been a while since we last mentioned so-called 'age-verification' laws
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 29, 2026
IRC logs for Saturday, August 29, 2026
Links 29/08/2026: Stop the Hate, Goldfish Myths, and xmpp.nz
Links for the day
Links 29/08/2026: Wave of Social Control Media Bans, Suno Data Breach Class Actions
Links for the day
Links 29/08/2026: Microsoft GitHub Outage (Again), "Displaying Ads Directly on Your Monitor", and "Election Deniers Could Soon Control Elections"
Links for the day
IBM is "Taking the PIP" (Piss), People 'Retire' 'Voluntarily' to "Focus on Family"
IBM has a billion bucks for 'the butcher', but not a million dollars for critical projects and initiatives in Free software
It Should be Uncontroversial to Say That Social Control Media is a Weapon
Democracy is not compatible with the likes of Kapo-Berg and MElon controlling public discourse of billions
Misuse of Bots (Now Sold as "Agents", "Hey Hi", "Automation", and "Efficiency")
They even try to rebrand robotics as "hey hi" and try to sell slop as "work"
Debian: Plagiarism OK, Just be "Responsible" About It
The result isn't the worst, but it's not good either
Don't Let Them Kill Activism
Are the oligarchs shutting the lid on activism and whistleblowers?
SLAPP Censorship - Part 165 Out of 200: Two Years Since My Wife and I Sued
In early September 2024 we hit back
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 28, 2026
IRC logs for Friday, August 28, 2026
Gemini Links 29/08/2026: Death Notice, Systems Biology, and Gopher
Links for the day
Links 28/08/2026: Chatbot Pushers Admit They're Used Heavily for Social Engineering Scams, Strong Backlash Against "Smart Glasses" (CCTV on Legs)
Links for the day
Michael Catanzaro's Latest Blog Post Affirms Rumours of Red Hat Changes and RAs/PIPs at IBM
reading between the lines, IBM is "spitting out" Red Hat staff
If Linux Was Written in Rust, 80% or More of Linux Developers Would Not Understand It (Same If It's Composed by LLM Slop)
The licence (GPL) is not enough when there are ways to bypass it
Gemini Links 28/08/2026: Absurd Tomodachi Summer, Screen Piggery, and Jugulans 1.0.3 Released
Links for the day
Links 28/08/2026: "UK Power Grid Has a Phantom Data Center Problem" and "Growth at All Costs is Cancer"
Links for the day
SLAPP Censorship - Part 164 Out of 200: Patent Troll SLAPPs, Defamation Trolls, and Stranglers From America
You start to wonder if the core issue is insecurity
Rumours of More PIPs and Layoffs at Confluent Just Months After IBM Bought It
It is meanwhile apparent IBM will have mass layoffs next week (September)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 27, 2026
IRC logs for Thursday, August 27, 2026
After Many Waves of PIPs (Silent Layoffs) IBM Makes Non-Silent Layoffs, Effective Next Week (September)
What we heard is turning out to be true