3 ms·
> break the disk encryption of a computer protected with tpm 2.0 + secureboot + luks w/tresor* On Windows (even modern versions IIRC) you can sniff the traffic
by temac 5y ago
> break the disk encryption of a computer protected with tpm 2.0 + secureboot + luks w/tresor*
On Windows (even modern versions IIRC) you can sniff the traffic (or maybe forge requests? I think it was simply sniffing though) to the TPM and get the keys to decrypt the HD, if there is no additional protection (like a PIN or password). Don't know if this is also applicable to Linux stacks. Kind of weird the interface has not been designed and/or programmed to resist to such attack, although of course password-less full disk decryption is often going to be less secure than with one, at least Macs are not subject to the same attack, I think?
- helpm33 5y agoFWIW, TPM 2.0 can encrypt the TPM traffic, so the attack by physically sniffing the TPM (https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-inside-the-company-network https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-in...) is no longer possible.
- temac 5y agoIt can but from the article, with a not so old Windows stack it seems that this encryption is not used: > At the time of this writing BitLocker does not utilize any encrypted communication features of the TPM 2.0 standard, which means any data coming out of the TPM is coming out in plaintext, including the decryption key for Windows. If we can grab that key, we should be able to decrypt the drive, get access to the VPN client config, and maybe get access to the internal network.