It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?
faulTPM: Exposing AMD fTPMs' Deepest Secrets
21–30 of 273 posts
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#22Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.
> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.
You are probably largely using x86_64 which come with the option to do so, but there has been a lot of push around moving to things like ARM for energy efficiency reasons.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#23To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#24"Our attack utilizes the AMD-SP’s vulnerability to voltage fault injection attacks [14] to extract a chip-unique secret from the targeted CPU."
"The attack requires access to the motherboard of the target system (4.1), particularly its SPI bus and voltage regulators."
In other words, it is required to open the laptop and connect custom (but cheap) hardware to the motherboard to disrupt its normal operation.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#25Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#26To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?
Mostly academia and nation states. Physical access will always be king and this provides one more avenue for adversaries to bypass encryption more easily.
No. Your wording suggests that once attackers gain physical access, all is lost. It is not true. With a passphrase based full disk encryption, if the passphrase is strong and the machine is powered off, physical access doesn't imply data access.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#27Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.
> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#28Earlier quoted context omitted.
Indeed it does, and this is just done by a team of researchers. Imagine what the NSA and their goons could get up to with 1000x more resources.
This is why you need to evaluate your threat model. Is the NSA out to get you? If so, I hope you aren't relying on HN for your security strategy. Are you worried about theft? Add a passphrase to your encrypted volume and don't rely on TPM. Worried about your coworker or family snooping on your computer and seeing your emails to your mistress? TPM is fine.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#29Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#30Earlier quoted context omitted.
> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.
Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.