Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

31–40 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#31

Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?

Mine, and I like it to stay that way. A TPM can be a valuable tool for protecting my data, making it difficult if not impossible for anyone to decrypt my drives. TPM+PIN is hard to beat.

TPM's true owner is the NSA, not you or I.

https://www.stat.rice.edu/~dobelman/kstorm.txt

https://news.ycombinator.com/item?id=6337282

https://www.militaryaerospace.com/computers/article/16711478...

https://www.businessinsider.com/leaked-german-government-war...

https://supplychaindigital.com/technology/nsa-trusted-comput...

https://redmondmag.com/articles/2013/08/22/windows-8-securit...

https://blogs.ncl.ac.uk/security/2015/07/29/on-the-trust-of-...

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#32

Earlier quoted context omitted.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I did find it odd that my Ryzen 7 1700X (8 cores, 16 threads, 3.4GHz) was suddenly "not good enough" to run the OS.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#33
post #16

Earlier quoted context omitted.

Yes, relevant in case of a lost device: "Motivated by Windows 11’s push to use the TPM for even more applications, we apply the vulnerability to Microsoft BitLocker and show the first fTPM-based attack against the popular Full Disk Encryption solution. BitLocker’s default TPM-only strategy manages – without any changes to the user experience – to swiftly step up a user’s security in the face of a lost or stolen devic…

Does this line imply then it is mostly a concern for Windows users? I don't mind only using Linux, it is Best in Slot for most tasks anyways.

ChromeOS also heavily relies on TPM for disk encryption, and unlike Windows doesn't even give you the option of adding a passphrase or pin on top of it.

And there's probably some large enterprises that use regular Linux desktops with LUKS/Btrfs/ZFS encryption in TPM only mode, to match their Windows setups. Systemd e.g. added systemd-cryptenroll with ergonomics comparable to Windows' Bitlocker enrollment.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#34
Gnarly, especially because these vulnerabilities seem unpatchable. Luckily, it seems TPM+PIN should remain safe if your PIN is difficult enough to brute-force, though.

As this includes an attack against the secure processor, does this also pose risks to any DRM keys?

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#35
post #6

To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?

TPM based disk encryption is mostly useful as theft protection, so that companies, education facilities or government agencies can provision 100,000 devices without having to match smartcards/fobs/disk passwords to devices and users. (Which often leads to terrible security practices, like backup passwords shared between devices etc.)

So cracking it in 3 hours by amateurs is pretty bad, because now even not too sophisticated thieves can start looking for crypto wallets or sensitive data to ransom.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#36
post #22

Earlier quoted context omitted.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

ARM that are microsoft certified will specifically not give you that option. You are probably largely using x86_64 which come with the option to do so, but there has been a lot of push around moving to things like ARM for energy efficiency reasons.

> there has been a lot of push around moving to things like ARM for energy efficiency reasons

There has? Where?

Specifically for Windows PCs, not chromebooks or apples.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#37

Earlier quoted context omitted.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I wish there was a linux distro made by people who love windows, not linux.

I've always felt that $BIG_BRAND_DISTRO+KDE got pretty close. It's still Linux, so not quite the same, but as far as look and feel, it's pretty close I think.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#38

Earlier quoted context omitted.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I did find it odd that my Ryzen 7 1700X (8 cores, 16 threads, 3.4GHz) was suddenly "not good enough" to run the OS.

Really crystallizes how what matters is "good enough" for Microsoft's goals, not the user's.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#39
post #28

Earlier quoted context omitted.

This is why you need to evaluate your threat model. Is the NSA out to get you? If so, I hope you aren't relying on HN for your security strategy. Are you worried about theft? Add a passphrase to your encrypted volume and don't rely on TPM. Worried about your coworker or family snooping on your computer and seeing your emails to your mistress? TPM is fine.

Well, considering I am 008, my threat model is quite high indeed! But ya, I was being hyperbolic. And HN has provided plenty of worthwhile info on the topic of OpSec over the years, do not be quick to discount. I would be a fool to reveal too much about my threat model but the reality is there exist many people who have reason to fear the NSA. Am I one of them? Nice try, NSA!

The popularity of hyperbole in HN discussions makes it easier for people to discount HN, both in drowning out useful information and in weakening discourse. Please reconsider in the future.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#40

Earlier quoted context omitted.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I wish there was a linux distro made by people who love windows, not linux.

There is a aphorism.

Bsd was made by people who love unix, linux was made by people who hate windows.

Post reply on HN