faulTPM: Exposing AMD fTPMs' Deepest Secrets
1–10 of 273 posts
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#2So I take this is more of a data exfiltration type of attack?
Edit: here is the POC https://github.com/PSPReverse/ftpm_attack
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#3Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#4Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#5Every time I think about the millions of computers that will be declared worthless this year, it makes me a little bit more angrier.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#6Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#7[1]: https://trustedcomputinggroup.org/wp-content/uploads/TCG_Sto...
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#8To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?
That sounds pretty practical.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#9To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?
> Bitlocker's TPM- only protector - can be defeated by an attacker with 2-3 hours of physical access to the target device That sounds pretty practical.
Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets
#10It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?
"Motivated by Windows 11’s push to use the TPM for even more applications, we apply the vulnerability to Microsoft BitLocker and show the first fTPM-based attack against the popular Full Disk Encryption solution. BitLocker’s default TPM-only strategy manages – without any changes to the user experience – to swiftly step up a user’s security in the face of a lost or stolen device. However, as our work complements the established at- tacks against dTPMs with an even more potent attack against AMD fTPMs, a TPM-only configuration lulls a non-technical user with high protection needs into a false sense of security."
"Users who fear a physical attacker with reasonable resources should opt for a TPM and PIN configuration. When BitLocker identifies that the underlying TPM is an fTPM, users should be urged to turn their PIN into a passphrase."