Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

121–130 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#122

It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?

One of the authors here. This attack is relevant if your machine is physically exposed to attacks, e.g., in an office environment or while traveling, and if you don't use any additional pre-boot passphrase to protect the disk (but rely solely on AMD's fTPM). When TPMs became popular, dedicated TPMs were mainly used, being a separate chip on the mainboard connected via the SPI or LPC bus. These were prone to (relative…

> These were prone to (relatively primitive) bus sniffing attacks, where you would hook up a Logic Analyzer to the bus, watch a regular boot procedure grab the disk key, and then use software like Dislocker to extract all data from a USB Live Linux or alike.

The TPM supports encrypted sessions, but they are opt in. See Parameter Encryption in the TPM spec. The issue is that Bitlocker doesn't use them for whatever reason. If Bitlocker turned on encrypted sessions, it would be not possible to sniff the key. It's crazy that Microsoft keep things insecure.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#123
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

There needs to be a way to measure and report on boot order. Hopefully there will be other options besides a TPM for this.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#124
post #84
post #29

Yet one more reason the Platform Security Processor is a nightmare and should be removed completely from future processors.

And IntelME.

I sometimes wonder if it'll be a selling point of Chinese CPUs in the future, "our CPU might not be the fastest, but it's the only one running at any given time!".

People don't need "flagship" CPUs for every single purpose. There is no reason why one cannot have a slower more private system for specific purposes, say general purpose computing, and the faster one with the autonomous network-aware CPU and OS be used for games only or something.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#125
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

It's called the TPM because it is trusted. The real question is, who is it that trusted that thing?

Trusted system is one whose failure would break a security policy. It's not about it being secure, it's about it breaking other things when it's broken.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#126
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

TPM allows government to request your data in the first place. So it should not be trusted by individuals from the beginning.

Uhh what? How does that work? Where do they request it? The TPM manufacturer? Microsoft?

TPMs aren't very secure and as a discrete component their connection to the CPU can be intercepted (unlike fTPM or apple's integrated solutions).. There's a big difference between having a deliberate backdoor and just a vulnerable design that can be exploited.

I haven't seen them accused of being backdoored. Intel's ME (and AMD's equivalent) perhaps but that's not the TPM.

TPMs can also be used to hide DRM keys from the user and I'm also opposed to that, but generally that stuff is hidden in other hardware. Like Google's wildvine stuff in mobile CPUs.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#128

Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?

Without a TPM servers can't verify that their genuine app is being used. https://developer.apple.com/documentation/devicecheck/valida...

Why would users want a server to know they're using their official crapware or an alternative/modded client that serves users better?

Surely the device should serve the interests of the user that pays for it, and not some random developer.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#129
Stupid question: was there no responsible disclosure and is there no cve assigned? Seems like a rather practical attack (or am I missing something?

Do the researchers consider it a known fact that that fTPM is broken by design and thus do think that nobody will get hurt? It would make sense to require an additional passphrase on fTPM devices for bitlocker. Was there a statement from Microsoft or AMD?

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#130
post #91

Earlier quoted context omitted.

yes

Source? That would be very shocking.

Why? The FBI pitched a fit over access to a shooter’s phone in the press a few years ago, then stopped.

Now, you have a multiple products on the market that can crack passcodes by utilizing flaws that allow you to brute force PINs, which are by default 6 digit numbers. (Despite most guidance demanding 8)

Post reply on HN