4 ms·
FWIW, TPM 2.0 can encrypt the TPM traffic, so the attack by physically sniffing the TPM (https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-inside-the-co
by helpm33 5y ago
FWIW, TPM 2.0 can encrypt the TPM traffic, so the attack by physically sniffing the TPM (https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-inside-the-company-network https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-in...) is no longer possible.
- temac 5y agoIt can but from the article, with a not so old Windows stack it seems that this encryption is not used: > At the time of this writing BitLocker does not utilize any encrypted communication features of the TPM 2.0 standard, which means any data coming out of the TPM is coming out in plaintext, including the decryption key for Windows. If we can grab that key, we should be able to decrypt the drive, get access to the VPN client config, and maybe get access to the internal network.