Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

51–60 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#51
post #16

Earlier quoted context omitted.

Yes, relevant in case of a lost device: "Motivated by Windows 11’s push to use the TPM for even more applications, we apply the vulnerability to Microsoft BitLocker and show the first fTPM-based attack against the popular Full Disk Encryption solution. BitLocker’s default TPM-only strategy manages – without any changes to the user experience – to swiftly step up a user’s security in the face of a lost or stolen devic…

Does this line imply then it is mostly a concern for Windows users? I don't mind only using Linux, it is Best in Slot for most tasks anyways.

if Linux full disk encryption would have a more user friendly UX a lot of Linux users would probably use that too

its a very convenient feature

through is not convenient to setup

and a lot of Linux users never trusted it to be secure, i. e. a lot of people expected an attack like this sooner or later

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#52
post #16

Earlier quoted context omitted.

Yes, relevant in case of a lost device: "Motivated by Windows 11’s push to use the TPM for even more applications, we apply the vulnerability to Microsoft BitLocker and show the first fTPM-based attack against the popular Full Disk Encryption solution. BitLocker’s default TPM-only strategy manages – without any changes to the user experience – to swiftly step up a user’s security in the face of a lost or stolen devic…

Does this line imply then it is mostly a concern for Windows users? I don't mind only using Linux, it is Best in Slot for most tasks anyways.

It could also be a concern for Linux users if they have configured their system to use systemd-cryptenroll (even with --tpm2-with-pin=yes or --fido2-with-client-pin=yes). The user is not asked for a secure passphrase in addition to having a TPM present. The user is just asked for a short PIN that is provided to the TPM2 or FIDO2 device and the device is not meant to return the secret without a valid PIN being provided.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#53

Earlier quoted context omitted.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I wish there was a linux distro made by people who love windows, not linux.

If I may suggest, ZorinOS is about as close to windows on Linux as it gets. Found it through a HN comment myself.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#54

Earlier quoted context omitted.

I did find it odd that my Ryzen 7 1700X (8 cores, 16 threads, 3.4GHz) was suddenly "not good enough" to run the OS.

It'll work fine, Microsoft even explains how to upgrade: https://support.microsoft.com/en-us/windows/installing-windo... They chose an arbitrary cut-off date for hardware support for their new OS. They decided not to support old stuff anymore and they had to pick a date/technology platform. It was always going to be arbitrary. In my opinion they should've picked a clearer distinction (i.e. require a certain level of…

True. It is not as though I've ever cared about what the vendor supports at home before.

Most of my machines were on a Linux distro before that decision, and Debian 12 is providing a good enough to me experience on the desktop, even gaming.

I'll probably just stay there indefinitely. Is that an upgrade? Subjective. I'm happier here.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#55

Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?

Mine, and I like it to stay that way. A TPM can be a valuable tool for protecting my data, making it difficult if not impossible for anyone to decrypt my drives. TPM+PIN is hard to beat.

[deleted]

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#56

Earlier quoted context omitted.

I did find it odd that my Ryzen 7 1700X (8 cores, 16 threads, 3.4GHz) was suddenly "not good enough" to run the OS.

Isn't this about Spectre/Meltdown vulns instead of the perf. specs?

IIRC it has more to do with that series of chip not having GMET (AMD Guest-Mode Execute Trap for NPT) which is used in Windows 10/11s virtualization based protection. Microsoft requires this option for all new PCs from their partners but you can install windows 11 and run it fine without this CPU feature (there is a performance hit if you leave virtualization based protection on though since it has to be done in software).

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#57

Earlier quoted context omitted.

I did find it odd that my Ryzen 7 1700X (8 cores, 16 threads, 3.4GHz) was suddenly "not good enough" to run the OS.

It'll work fine, Microsoft even explains how to upgrade: https://support.microsoft.com/en-us/windows/installing-windo... They chose an arbitrary cut-off date for hardware support for their new OS. They decided not to support old stuff anymore and they had to pick a date/technology platform. It was always going to be arbitrary. In my opinion they should've picked a clearer distinction (i.e. require a certain level of…

It can work yes but AMD chips didn't get GMET until Zen2 so if you leave virtualization based protection on you might see a performance hit.

From Microsoft's website:

>Memory integrity works better with Intel Kabylake and higher processors with Mode-Based Execution Control, and AMD Zen 2 and higher processors with Guest Mode Execute Trap capabilities. Older processors rely on an emulation of these features, called Restricted User Mode, and will have a bigger impact on performance.

https://learn.microsoft.com/en-us/windows/security/threat-pr...

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#58

Earlier quoted context omitted.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

You can install W11 without a TPM with a workaround. Microsoft should be forced to allow it by default.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#59

It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?

Access/privileges to execute on the host is required. I, personally, would not feel concerned unless I was a TPM user and knew I was a specific target.

you also need to connect (cheap) hardware to your motherboard

this makes it very very unlikely to be usable in a virus or remote attack

but if you lose your arm laptop and didn't use a encryption password you might want to consider your data leaked

also I would treat Intel cpus the same, Intel having a similar vulnerability is not unlikely

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#60

The most important sentences of the article: "Our attack utilizes the AMD-SP’s vulnerability to voltage fault injection attacks [14] to extract a chip-unique secret from the targeted CPU." "The attack requires access to the motherboard of the target system (4.1), particularly its SPI bus and voltage regulators." In other words, it is required to open the laptop and connect custom (but cheap) hardware to the motherboa…

> voltage fault injection attacks

What's old is new again!

Post reply on HN