Live data from Hacker News

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

seclists.org

11–20 of 99 posts

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#12

AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…

It's not related to Secure Boot, no, so there's no requirement for physical access.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#14

Earlier quoted context omitted.

I had read somewhere that AMD PSP does not have Internet access.

It does, DASH is also arguably much less secure than Intel's RMT.

Hmm, I did not know this. Good to know!

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#16
post #4

Earlier quoted context omitted.

I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?

Yes, AMD's PSP runs a full OS which was made by Trustonic.

Trustonic is about as trustworthy a name as "Safecorp" or something similar. The name itself is just one big red flag.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#17
post #15

2018 is going to be a great year for zero day exploits.

Hopefully 2018 will be the year where CPU manufacturers finally start taking security seriously.

Yeah sure and I bet this will be the year of the Linux Desktop, too.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#18
post #16

Earlier quoted context omitted.

Yes, AMD's PSP runs a full OS which was made by Trustonic.

Trustonic is about as trustworthy a name as "Safecorp" or something similar. The name itself is just one big red flag.

They are probably the largest TEE* supplier AFIK even bigger than Intel; they are pretty much the Java of the TEE world.

It’s a joint venture between ARM, Gemalto and a few other companies iirc.

*Trusted Execution Environment

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#19
post #9

AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…

The PSP is already quite long in the tooth. I think AMD will switch to ARM's recently announced "SecurCore" soon, just like Qualcomm did for the Snapdragon 845: https://developer.arm.com/products/processors/cortex-m/sc300...

[deleted]

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#20
post #17
post #15

Earlier quoted context omitted.

Hopefully 2018 will be the year where CPU manufacturers finally start taking security seriously.

Yeah sure and I bet this will be the year of the Linux Desktop, too.

Gentlemen, may I interest you in a gently-used bridge over a pristine river in New York City?
Post reply on HN