Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

61–70 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#61

Earlier quoted context omitted.

Mostly academia and nation states. Physical access will always be king and this provides one more avenue for adversaries to bypass encryption more easily.

> Physical access will always be king No. Your wording suggests that once attackers gain physical access, all is lost. It is not true. With a passphrase based full disk encryption, if the passphrase is strong and the machine is powered off, physical access doesn't imply data access.

You still have to defend against cold boot attacks or very sophisticated hardware implants:

https://www.bloomberg.com/news/features/2018-10-04/the-big-h...

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#63
post #44

Earlier quoted context omitted.

One of the authors here. This attack is relevant if your machine is physically exposed to attacks, e.g., in an office environment or while traveling, and if you don't use any additional pre-boot passphrase to protect the disk (but rely solely on AMD's fTPM). When TPMs became popular, dedicated TPMs were mainly used, being a separate chip on the mainboard connected via the SPI or LPC bus. These were prone to (relative…

This is important because one purpose of TPMs is to prevent the owner of the machine from doing certain things (as in Digital Rights Management). And the owner of the machine presumably has physical access.

No...

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#64

Earlier quoted context omitted.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

I wish there was a linux distro made by people who love windows, not linux.

There have been several, but what makes Windows Windows is the ecosystem, and no distro can replicate that.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#65

Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?

Mine and I want a TPM, it's a device essential for modern laptop security.

_Even if you would be able to control every bit of firmware on your computer and there was no DRM or similar you still would want a TPM!_

through potential a different implementation and not some of the features build on top of it

like something like a TKey integrated into your CPU with some additions for securing the boot chain (including the EFI itself) would probably be a convenient, simple, way to have the necessary security without many of the problems ... or did I just reinvent TPM ?

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#66

Earlier quoted context omitted.

> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.

Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.

Microsoft said they were ending support in 2025, which is what 8 year life for the OS?

I don't even think Apple hits 8 for OSX updates. They obsolete the laptops more quickly than that, even if they do hit 6-7 years regularly.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#67
post #36
post #22

Earlier quoted context omitted.

ARM that are microsoft certified will specifically not give you that option. You are probably largely using x86_64 which come with the option to do so, but there has been a lot of push around moving to things like ARM for energy efficiency reasons.

> there has been a lot of push around moving to things like ARM for energy efficiency reasons There has? Where? Specifically for Windows PCs, not chromebooks or apples.

Not got a reference but one of the new Lenovo ARM laptops claims to have 26 hour battery life. If true then that's pretty compelling.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#68
post #67
post #36

Earlier quoted context omitted.

> there has been a lot of push around moving to things like ARM for energy efficiency reasons There has? Where? Specifically for Windows PCs, not chromebooks or apples.

Not got a reference but one of the new Lenovo ARM laptops claims to have 26 hour battery life. If true then that's pretty compelling.

Not running any software is very helpful for battery life.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#69
post #44

Earlier quoted context omitted.

One of the authors here. This attack is relevant if your machine is physically exposed to attacks, e.g., in an office environment or while traveling, and if you don't use any additional pre-boot passphrase to protect the disk (but rely solely on AMD's fTPM). When TPMs became popular, dedicated TPMs were mainly used, being a separate chip on the mainboard connected via the SPI or LPC bus. These were prone to (relative…

This is important because one purpose of TPMs is to prevent the owner of the machine from doing certain things (as in Digital Rights Management). And the owner of the machine presumably has physical access.

There aren't really any mainstream DRM systems that use a general computing platform TPM, precisely because they have a terrible track record of being breached.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#70
post #5

Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.

Debian Stable welcomes refugees:

https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/

(Or, for laptops with closed WiFi and no Ethernet, use this installer: https://cdimage.debian.org/cdimage/unofficial/non-free/cd-in... )

Post reply on HN