> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…
Funnily enough, in TPM 2.0 there's way around MITM attacks like that - you can establish encrypted connection between TPM and CPU, which outside first-time configuration (which should happen in controlled environment anyway) should provide reasonable roadblock to successful MITM attack. But CPU-side software needs to use it, and without default well-known keys...
TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
11–20 of 136 posts
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#12Earlier quoted context omitted.
> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?
There might be hardware "solutions" to that problem.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#13> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…
Bitlocker is traditionally the implementation susceptible for this attack, but for that I'll just defer to Chris Fenner.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#14Earlier quoted context omitted.
> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?
Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#15> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…
> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?
The screen/keyboard is not authenticated to the user, and TPM is not capable of fixing that.
It doesn't require some state actor to do that. Just money.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#16Earlier quoted context omitted.
Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.
And then return me my laptop and steal it again?
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#17Earlier quoted context omitted.
Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.
And then return me my laptop and steal it again?
It's highly unlikely that you would be the target of such a highly sophisticated attack, but a hacker could get into a place where you left your computer without surveillance (such as your home or a hotel) for about 15 minutes, and install it inside your computer.
If you think you could be the target of such an attack, you could maybe enable an alert in the settings of your UEFI if your computer has been opened (I know that my ThinkPad has that option), or the better option is to always keep your laptop with you.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#18Earlier quoted context omitted.
And then return me my laptop and steal it again?
You have to consider what kind of risk you are protecting yourself against. It's highly unlikely that you would be the target of such a highly sophisticated attack, but a hacker could get into a place where you left your computer without surveillance (such as your home or a hotel) for about 15 minutes, and install it inside your computer. If you think you could be the target of such an attack, you could maybe enable…
It seems like these security discussions always devolve into rather funny moving of goalposts without actually considering how much work each exploit requires.
Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
#19Ah, the tweezers strike again, just not for Nintendo this time. Truly the most universal hardware hacking tool.