4 ms·
The plain text SPI seems to be guilty. Could fTPM help?
by yuuta 5y ago
The plain text SPI seems to be guilty. Could fTPM help?
- mjg59 5y agoYes, this is a (rare) case where fTPM has better security properties. For context: fTPM refers to a software-based implementation of a TPM running in an execution environment the OS has no direct access to. On Intel hardware, this is on the Management Engine - depending on the specific CPU range, this will either be on the CPU package or in the motherboard chipset. On AMD systems, it's running in the Platform Security Processor, a separate ARM core that's on the CPU package. For ARM systems, it's generally running on the main execution cores but in the TrustZone environment. In all these scenarios the TPM code is running in the same environment as a bunch of other code that exposes some additional attack surface, so seems less appealing than a discrete TPM. On the other hand, the sort of attack described here is probably impractical unless you have much higher end equipment.
- deleted 5y ago[deleted]