Live data from Hacker News

TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

mkukri.xyz

11–20 of 136 posts

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#11
post #3
post #2

> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…

Funnily enough, in TPM 2.0 there's way around MITM attacks like that - you can establish encrypted connection between TPM and CPU, which outside first-time configuration (which should happen in controlled environment anyway) should provide reasonable roadblock to successful MITM attack. But CPU-side software needs to use it, and without default well-known keys...

vast majority of fTPM 2.0's are chips placed on the CPU die anyway

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#12
post #4

Earlier quoted context omitted.

> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?

There might be hardware "solutions" to that problem.

I believe https://xkcd.com/538/ is the comic you're looking for.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#13
post #2

> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…

BUS interposers are trivially defeated with encrypted sessions and a PIN.

Bitlocker is traditionally the implementation susceptible for this attack, but for that I'll just defer to Chris Fenner.

https://www.dlp.rip/tpm-genie

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#14
post #6
post #4

Earlier quoted context omitted.

> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?

Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.

Glitter nailpolish on your machine seams/screws and tamper detection. Keyboard sniffing is not as trivial as people make it out to be.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#15
post #4
post #2

> If attacker have physical access, the discrete TPM is an attack surface anyway and even a known attack already. If you're wondering what they mean by this, [1] has been around since 2018. It's not unusual for a motherboard to put the TPM on a removable module, so you don't even have to desolder the chip to MITM the communications. The most recent Intel and AMD CPUs have "firmware TPMs" that run in the CPU's so-call…

> Of course, that doesn't mean you're protected against attackers who have physical access to the machine; they can simply install a keylogger. How would that attack work if someone stole my Ryzen powered laptop with full disk encryption, TPM2.0 and secure boot with firmware password enabled?

I'd buy you an replacement laptop of the same model and then install a rendering of your boot process and password prompt on it. Doing a switcheroo and waiting in my bunker until the fake sends me the password you entered.

The screen/keyboard is not authenticated to the user, and TPM is not capable of fixing that.

It doesn't require some state actor to do that. Just money.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#16
post #10
post #6

Earlier quoted context omitted.

Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.

And then return me my laptop and steal it again?

Bluetooth keyloggers are a thing. The attacker would need to be nearby.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#17
post #10
post #6

Earlier quoted context omitted.

Probably not the most practical attack, but it is very possible to MITM the connection between the keyboard itself and the motherboard.

And then return me my laptop and steal it again?

You have to consider what kind of risk you are protecting yourself against.

It's highly unlikely that you would be the target of such a highly sophisticated attack, but a hacker could get into a place where you left your computer without surveillance (such as your home or a hotel) for about 15 minutes, and install it inside your computer.

If you think you could be the target of such an attack, you could maybe enable an alert in the settings of your UEFI if your computer has been opened (I know that my ThinkPad has that option), or the better option is to always keep your laptop with you.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#18
post #17
post #10

Earlier quoted context omitted.

And then return me my laptop and steal it again?

You have to consider what kind of risk you are protecting yourself against. It's highly unlikely that you would be the target of such a highly sophisticated attack, but a hacker could get into a place where you left your computer without surveillance (such as your home or a hotel) for about 15 minutes, and install it inside your computer. If you think you could be the target of such an attack, you could maybe enable…

I'm mostly asking because the original poster was painting a process that can be sniffed off the bus (that is - buy a stolen laptop off ebay, try to boot it, sniff the key off the bus) with a process that requires active targeting and multiple breakins to work as equivalent.

It seems like these security discussions always devolve into rather funny moving of goalposts without actually considering how much work each exploit requires.

Re: TPM GPIO fail: How bad OEM firmware ruins Intel TPM security

#20

Earlier quoted context omitted.

There might be hardware "solutions" to that problem.

I believe https://xkcd.com/538/ is the comic you're looking for.

Lol that’s also true, though I was alluding to hardware sitting next to/after the keyboard. But whatever is easier I guess.
Post reply on HN