Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

241–250 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#241

Earlier quoted context omitted.

Interesting it is the Chinese processors (e.g. Allwinner, T-Head, Rockchip) that happen to be free of this secure boot garbage by default. If you want to you can blow an efuse (with power applied to the VPP pin) and enable secure boot. But otherwise it's off. I am waiting for a high performance ARM or RISC-V chip that's on par with AMD and Intel performance. One without secure boot. The moment that comes out, my Ryze…

On par? Depends which year you're targeting and perhaps what applications. If you mean on par with current year then it'll be a long time before that happens because AMD and Intel are able to run power-hungry while ARM and RISC-V try to use less power.

>If you mean on par with current year then it'll be a long time

Tenstorrent Ascalon, a RISC-V CPU TBA 2024, has performance competitive with projected Zen5 performance, while using less power.

As Zen5 is also TBA 2024, they'll be on par in the same year.

RISC-V is inevitable.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#242
post #134
post #129

Stupid question: was there no responsible disclosure and is there no cve assigned? Seems like a rather practical attack (or am I missing something? Do the researchers consider it a known fact that that fTPM is broken by design and thus do think that nobody will get hurt? It would make sense to require an additional passphrase on fTPM devices for bitlocker. Was there a statement from Microsoft or AMD?

From the paper: "All security-relevant findings discussed in this paper were responsibly disclosed to AMD, Microsoft, and the systemd-cryptenroll maintainers. The systemd-cryptenroll maintainers quickly got back to us to discuss specific mitigation strategies."

[deleted]

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#243
post #143

Earlier quoted context omitted.

Erm… yes, actually. For DRM to work, it has to be running in a trusted environment where the user can’t just load up a debugger as superuser and read the keys from memory. The way you do that is by using secure boot to ensure that you are running a trusted kernel that enforces appropriate access controls… which requires TPM. One of the main selling points of TPM is that you have chain of trust to ensure the boot proc…

Author here: TPMs are not a TEE (trusted execution environment), and the TEE included in AMD's CPUs function completely separately from the TPM. So you could disable the TPM and still have the TEE run DRM code. The fact that both TEE and fTPM run on the PSP (or AMD-SP) might add a little confusion, but is nevertheless interesting.

Thanks for this clarification!

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#244

Earlier quoted context omitted.

Windows, Linux, OpenBSD - it doesn't matter. Without a TPM you're vulnerable to trivial attacks (Evil Maid), far easier than the one in this article.

So.... Take your laptop with you everywhere? When did we start creating nightmarish system complexity to guard against attacks that are generally exceedingly rare....oh wait. Forgot where I was.

That cannot be a serious proposal. These attacks can and do happen, and it's in our interest to design systems that make them as hard as possible.

I'll take "nightmarish complexity" that puts these attacks outside of the scope of a technically savvy teenager over having to carry my machine with me everywhere I go, any day of the week.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#245

Earlier quoted context omitted.

Which is amazing since windows 11 is full of mentions of green energy, lowering energy consumption and asking you to lower screen brightness to lower carbon emissions. Total green washing when you consider the gigantic amounts of ewaste that arbitrary cut off date will lead to. It's just funny tbh, like I get it's most likely very different teams working on those things but it's tone deaf at best. But hey at least th…

This is what most of the consumer facing eco trends feel like. Kool-aid Jammers are my latest laugh. Plastic pouch. Plastic straw wrapper. Paper straw. Right, the straw was the enemy here?

I for one think plastic straws taste bad.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#246

Earlier quoted context omitted.

TPM 2.0 is a fantastic spec. There's little that's wrong with it. Even the bus sniffing vulnerabilities w/ dTPMs aren't TPM's fault but the BMC's and BIOS', as there is absolutely a way to encrypt and authenticate secrets to/from the TPM. Reinventing this wheel will probably lose a lot of good things. People who reinvent wheels often fail to understand what came before.

Encrypting bus traffic? What kind of mission impossible spy is this supposed to protect from?

That's how console jailbreak mods have worked in the past.

The important keyword is authenticated though. If it's not authenticated you can corrupt it.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#247

Earlier quoted context omitted.

The first link said nothing about TPMs. The second link is nonsense. The third link says the NSA "teams" with the TCG, which could be concerning indeed, but there's no details there. The fourth link is light on details and full of FUD. The fifth link says roughly the same as the third, and is equally light on details. The sixth link is like the fourth but it does have some actually useful information that says you're…

>Er, well, this fails because there is no way to compress cryptographic material, and we're talking about random or pseudo-random keys being compressed (which, you can't) then encrypted. So this particular idea fails immediately. Excuse me, but wtf. That's BS. Cryptographic material is nothing but data . A Huffman encode will work on a number that happens to be a public key just as happily as it will a anything else.…

An RSA public key is a prime number. How are you going to compress a prime number?

Encrypted material should not be compressable because it needs to appear random no matter what the unencrypted contents are, otherwise you have information about those contents. (You can trade off between the security and compressability, but shouldn't.)

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#249
post #134
post #129

Stupid question: was there no responsible disclosure and is there no cve assigned? Seems like a rather practical attack (or am I missing something? Do the researchers consider it a known fact that that fTPM is broken by design and thus do think that nobody will get hurt? It would make sense to require an additional passphrase on fTPM devices for bitlocker. Was there a statement from Microsoft or AMD?

From the paper: "All security-relevant findings discussed in this paper were responsibly disclosed to AMD, Microsoft, and the systemd-cryptenroll maintainers. The systemd-cryptenroll maintainers quickly got back to us to discuss specific mitigation strategies."

Thx. I overlooked this part. So AMD and Microsoft simply ignored it and leave customers unprotected. Wow.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#250

Earlier quoted context omitted.

This is what most of the consumer facing eco trends feel like. Kool-aid Jammers are my latest laugh. Plastic pouch. Plastic straw wrapper. Paper straw. Right, the straw was the enemy here?

I for one think plastic straws taste bad.

You prefer the taste of wet paper and a little wax, as it falls apart in your mouth?
Post reply on HN