3 ms·
Really good article. It's interesting that TPM communicate is over SPI and also unencrypted. Goes to show you're only as strong as the weakest link.
by PenguinCoder 5y ago
Really good article. It's interesting that TPM communicate is over SPI and also unencrypted. Goes to show you're only as strong as the weakest link.
- MisterTea 5y agoThat's how the original "unhackable" Xbox was broken. The encrypted firmware was decrypted by hardware in the south-bridge but sent unencrypted to the RAM via the open hyper transport bus. So someone hooked a fast logic analyzer to the bus and read the firmware during boot.
- monocasa 5y agoWell, the encrypted second stage firmware was decoded in software by a plaintext ROM stored in the southbridge that contained the keys. That 512 byte southbridge ROM also didn't do quality asymmetric crypto, so by dumping the RC4 key (and in later revisions the TEA hash digest) they were able to decrypt the main firmware in flash and replace it with arbitrary code. With today's consoles, it's sort of assumed that the attackers will get read access to the first stage boot loader, so they use public keys to validate any stages not originating from the CPU die itself. Then attackers can't replace follow on stages even with read access to the first stage.
- mappu 5y agoMany devices don't have a physically separate TPM but only use an fTPM on the CPU, which would block this attack.
- lostmsu 5y agoSounds like fTPM might be preferred to separate modules.