3 ms·
There are ways to generate an anonymous proof that a TPM module is certified genuine by its manufacturer, without leaking the actual identity of the individual
by chousuke 5y ago
There are ways to generate an anonymous proof that a TPM module is certified genuine by its manufacturer, without leaking the actual identity of the individual device.
Using TPM2 in VMs means you either pass through the hardware to the VM or use a software TPM module that's managed by the hypervisor.
I've had to dig in to TPM2 somewhat lately, and honestly the biggest problem with it is that it's too damn flexible, so it's really difficult to tell how to use one properly. There are a dozen concepts that you need to understand before you can even begin to make sense of any documentation.
- raxxorrax 5y agoThere is a key for the TPM chip that authenticates it. It is a unique identifier you cannot change. How can this be anonymized?
- gruez 5y agoAFAIK it's accomplished by having two keys in the TPM. One is unique to the TPM, and the other is unique to the manufacturer/batch of TPMs.
- raxxorrax 5y agoTrue, I found it in the manual. There is the ECC-based Direct Anonymous Attestation, but the paper is behind a paywall right now. My country (GER) currently wants to force OS developers to block sites not intended for children by default. TPM is a mechanism that could facilitate such restrictions. Imagine all content on the net would check that the boot loader of your device is locked and that you use a state approved OS. See the dangers here? Even if the chance of success is low, boot sector attacks by ransomware, currently the most prominent threat, are extreme rare, I don't know of any case to be honest. This infrastructure decreases security for free and general computing to such a degree, that the threat from boot sector or bios attacks is laughable at best.