Live data from Hacker News

faulTPM: Exposing AMD fTPMs' Deepest Secrets

arxiv.org

1–10 of 273 posts

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#2
"security properties of the TPM - like Bitlocker's TPM- only protector - can be defeated by an attacker with 2-3 hours of physical access to the target device"

So I take this is more of a data exfiltration type of attack?

Edit: here is the POC https://github.com/PSPReverse/ftpm_attack

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#8
post #6

To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?

> Bitlocker's TPM- only protector - can be defeated by an attacker with 2-3 hours of physical access to the target device

That sounds pretty practical.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#9
post #6

To anyone with a bit more breadth on this topic: is this as terrible as it sounds or more just in the realm of academia and nation-states?

> Bitlocker's TPM- only protector - can be defeated by an attacker with 2-3 hours of physical access to the target device That sounds pretty practical.

Indeed it does, and this is just done by a team of researchers. Imagine what the NSA and their goons could get up to with 1000x more resources.

Re: faulTPM: Exposing AMD fTPMs' Deepest Secrets

#10

It says any TPM can be defeated in 2-3 hrs with physical access. Is the AMD one different? Can it be defeated over networks? And is this something I should be concerned about since I just bought a new AMD machine?

Yes, relevant in case of a lost device:

"Motivated by Windows 11’s push to use the TPM for even more applications, we apply the vulnerability to Microsoft BitLocker and show the first fTPM-based attack against the popular Full Disk Encryption solution. BitLocker’s default TPM-only strategy manages – without any changes to the user experience – to swiftly step up a user’s security in the face of a lost or stolen device. However, as our work complements the established at- tacks against dTPMs with an even more potent attack against AMD fTPMs, a TPM-only configuration lulls a non-technical user with high protection needs into a false sense of security."

"Users who fear a physical attacker with reasonable resources should opt for a TPM and PIN configuration. When BitLocker identifies that the underlying TPM is an fTPM, users should be urged to turn their PIN into a passphrase."

Post reply on HN