Earlier quoted context omitted.
> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.
Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.
faulTPM: Exposing AMD fTPMs' Deepest Secrets
71–80 of 273 posts
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#72Earlier quoted context omitted.
> Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier. What is this a reference to? Every computer I've found will let you boot into the bios and disable secure boot or add new keys to the trust store.
Microsoft is edging closer and closer to dropping support for Windows 10(even a computer I built in 2017 that's still running perfectly fine can't upgrade). But for many users, changing to another OS besides Windows is tantamount to not functioning, so planned obsolescence continues apace.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#73Earlier quoted context omitted.
This is important because one purpose of TPMs is to prevent the owner of the machine from doing certain things (as in Digital Rights Management). And the owner of the machine presumably has physical access.
no they are for boot chain security which is an essential featur for any laptop TPM by itself never prevents anyone from doing anything but it's used with features like secure boot, but as long as they fully implement the spec they don't prevent you from doing with your laptop what you want as long as you don't install software which does so secure enclave and similar used for DRM isn't directly a TPM feature but mor…
For DRM to work, it has to be running in a trusted environment where the user can’t just load up a debugger as superuser and read the keys from memory.
The way you do that is by using secure boot to ensure that you are running a trusted kernel that enforces appropriate access controls… which requires TPM.
One of the main selling points of TPM is that you have chain of trust to ensure the boot process wasn’t tampered by a rogue boot loader that modified your code. And, yes, that has security benefits as well, but don’t for a second think that DRM wasn’t a major consideration.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#74Earlier quoted context omitted.
Mostly academia and nation states. Physical access will always be king and this provides one more avenue for adversaries to bypass encryption more easily.
> Physical access will always be king No. Your wording suggests that once attackers gain physical access, all is lost. It is not true. With a passphrase based full disk encryption, if the passphrase is strong and the machine is powered off, physical access doesn't imply data access.
This is _trivial_ for any mildly sophisticated attacker.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#75> Our attacks have shown that an fTPM cannot sufficiently protect its internal state against firmware or physical attacks. In such a scenario, a passphrase-only key protector of reasonable length provides better security than a TPM-only protector with a numeric PIN (5.3.1). This is in stark contrast to Microsoft’s claim that “BitLocker provides the most protection when used with a Trusted Platform Module” [29] (see a…
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#76Honestly TPM is probably creating more bad than good at this point. Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#77Why not simply abandon TPM and focus on making simple, trustable, massively parallel general-purpose hardware without backdoors for spy agencies and corporations? Whose computer is this, anyway?
Mine, and I like it to stay that way. A TPM can be a valuable tool for protecting my data, making it difficult if not impossible for anyone to decrypt my drives. TPM+PIN is hard to beat.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#78trust only open-source software crypto
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#79Earlier quoted context omitted.
This is important because one purpose of TPMs is to prevent the owner of the machine from doing certain things (as in Digital Rights Management). And the owner of the machine presumably has physical access.
There aren't really any mainstream DRM systems that use a general computing platform TPM, precisely because they have a terrible track record of being breached.
Part of that is things like:
* Don’t load an unsigned (or wrongly-signed) GPU driver, because it might be modified to allow a user to read from framebuffer memory after content has been decrypted.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#80> Our attacks have shown that an fTPM cannot sufficiently protect its internal state against firmware or physical attacks. In such a scenario, a passphrase-only key protector of reasonable length provides better security than a TPM-only protector with a numeric PIN (5.3.1). This is in stark contrast to Microsoft’s claim that “BitLocker provides the most protection when used with a Trusted Platform Module” [29] (see a…
Not only do they hide it under a group policy even when you enable an "Enhanced PIN" there is a maximum length of 20.