AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
11–20 of 99 posts
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#12AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#13I think "remote" here means "host to TPM chip". Which is still bad, but not on the level of "install a rootkit on a powered-off machine" like some of the Intel ME exploits.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#14Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#152018 is going to be a great year for zero day exploits.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#16Earlier quoted context omitted.
I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?
Yes, AMD's PSP runs a full OS which was made by Trustonic.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#17Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#18Earlier quoted context omitted.
Yes, AMD's PSP runs a full OS which was made by Trustonic.
Trustonic is about as trustworthy a name as "Safecorp" or something similar. The name itself is just one big red flag.
It’s a joint venture between ARM, Gemalto and a few other companies iirc.
*Trusted Execution Environment
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#19AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
The PSP is already quite long in the tooth. I think AMD will switch to ARM's recently announced "SecurCore" soon, just like Qualcomm did for the Snapdragon 845: https://developer.arm.com/products/processors/cortex-m/sc300...
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#20Earlier quoted context omitted.
Hopefully 2018 will be the year where CPU manufacturers finally start taking security seriously.
Yeah sure and I bet this will be the year of the Linux Desktop, too.