Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

21–30 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#21

It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?

Access/privileges to execute on the host is required. I, personally, would not feel concerned unless I was a TPM user and knew I was a specific target.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#22
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

ARM that are microsoft certified will specifically not give you that option.

You are probably largely using x86_64 which come with the option to do so, but there has been a lot of push around moving to things like ARM for energy efficiency reasons.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#23
post #6

To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?

Not an expert, but I think the biggest exposure most consumers might face is lost/stolen devices where it's conceivable an adversary could have physical access.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#24
The most important sentences of the article:

"Our attack utilizes the AMD-SP’s vulnerability to voltage fault injection attacks [14] to extract a chip-unique secret from the targeted CPU."

"The attack requires access to the motherboard of the target system (4.1), particularly its SPI bus and voltage regulators."

In other words, it is required to open the laptop and connect custom (but cheap) hardware to the motherboard to disrupt its normal operation.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#25

Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?

Mine, and I like it to stay that way. A TPM can be a valuable tool for protecting my data, making it difficult if not impossible for anyone to decrypt my drives. TPM+PIN is hard to beat.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#26
post #6

To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?

Mostly academia and nation states. Physical access will always be king and this provides one more avenue for adversaries to bypass encryption more easily.

> Physical access will always be king

No. Your wording suggests that once attackers gain physical access, all is lost. It is not true. With a passphrase based full disk encryption, if the passphrase is strong and the machine is powered off, physical access doesn't imply data access.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#27
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

I've had laptops where secure boot was permanently on unless you used legacy bios, and I've fixed several, both PCs and laptops, where there was no option to disable secure boot or use legacy bios. This was some years ago, and the situation has improved a lot since then.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#28
post #9

Earlier quoted context omitted.

Indeed it does, and this is just done by a team of researchers. Imagine what the NSA and their goons could get up to with 1000x more resources.

This is why you need to evaluate your threat model. Is the NSA out to get you? If so, I hope you aren't relying on HN for your security strategy. Are you worried about theft? Add a passphrase to your encrypted volume and don't rely on TPM. Worried about your coworker or family snooping on your computer and seeing your emails to your mistress? TPM is fine.

Well, considering I am 008, my threat model is quite high indeed! But ya, I was being hyperbolic. And HN has provided plenty of worthwhile info on the topic of OpSec over the years, do not be quick to discount. I would be a fool to reveal too much about my threat model but the reality is there exist many people who have reason to fear the NSA. Am I one of them? Nice try, NSA!

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#30

Earlier quoted context omitted.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I wish there was a linux distro made by people who love windows, not linux.
Post reply on HN