6 ms·
Break into this CEO’s laptop to steal company secrets and plant malware
- staticassertion 5y agoUltimately I guess the best solution here is something like intel PTT where the TPM is on-chip, or otherwise some sort of soldered shared secret / keys that the TPM and CPU have for encrypted communications over the bus.
- gambiting 5y agoRyzen CPUs also have the TPM itegrated directly into the CPU.
- martin_a 5y agoWhat fascinates me most is how quick this can be done. If you do your "homework" and find out which device needs to be attacked, you can really set everything up in advance and can be done in no time. Amazing and shocking at the same time.
- fxtentacle 5y agoTLDR: Sniff the Bitlocker secret key from the SPI bus using a logic analyzer. Then, Kali can decrypt the HDD.
- wiliaonson 5y agoI do hope that it is secured enough to withstand attacks.
- Gargyle 5y agoOn Dell devices in that age range I saw a bitlocker mode that used the drive controllers own encryption feature. I dont remember if the key was provided by tpm but they used attestation. I dont know if they had a key unwrap dependent on that attestation or if it was just a postfactum check that is submitted to management servers. In that course I have seen a bunch of blog posts where people found bugdoors or easy auth bypasses in these drive controller encryption schemes. Is that still a thing?
- tbyehl 5y agoMicrosoft released an update in 2019 to no longer default to using the self-encrypting features of devices. <https://support.microsoft.com/en-us/topic/september-24-2019-kb4516071-os-build-16299-1420-5648029d-8d1c-ed9e-b72c-63c6fee30bff https://support.microsoft.com/en-us/topic/september-24-2019-...>
- ginko 5y agoShouldn't the TPM/hard disk be password protected? What's even the point of the TPM when you can just sniff out the key without it?
- michaelt 5y ago> What's even the point of the TPM Normal full disk encryption needs you to enter two passwords - one to decrypt the disk, another a minute or two later to log into the operating system. Your corporate IT helpdesk can remotely reset the latter password if you forget it, but the former can't be remotely reset. And if several people need to be able to boot a shared computer, they need to share the disk encryption password (which isn't winning any security awards). Between the TPM and Secure Boot, the intention is that you sacrifice a certain amount of security - but in exchange, you can have only a single password prompt, a password IT can remotely reset, and no shared boot password.
- ginko 5y ago>And if several people need to be able to boot a shared computer, they need to share the disk encryption password (which isn't winning any security awards). At least with LUKS you can have multiple passwords for unlocking a disk so you can have one master password and user password(s) for the same machine. Having to enter two passwords doesn't seem like a big issue for high security HW like a CEO's laptop. In fact that's standard procedure at my company.
- sva_ 5y agoIf you use LUKS full disk encryption you can also just suspend it while logged in, so you only need to enter the LUKS password on resume.
- Sebb767 5y ago> At least with LUKS you can have multiple passwords for unlocking a disk Luks implements this by encrypting the actual key multiple times, once with each password. So if one person turns evil before you remove their password or a password is leaked, you can still consider the disk compromised.
- mtlynch 5y agoThis is a little silly because this assumes that BitLocker is configured for TPM-only rather than requiring a TPM PIN/password. If there's a TPM password, this attack becomes infeasible because the TPM won't release the keys without the password. And you generally can't brute force the TPM without triggering the hardware lockout. The company's IT department can require TPM+Password in Group Policy so that every system in the organization uses TPM+Password, but I guess you could have a stubborn CEO who demands a less secure policy. As of Windows 8, it was possible to replace ciphertext on a BitLocker-encrypted drive to compromise known Windows binaries.[0] This would allow the attacker to take control of the system on next boot, though I don't know if those attacks are still practical. [0] https://cryptoservices.github.io/fde/2014/12/08/code-execution-in-spite-of-bitlocker.html https://cryptoservices.github.io/fde/2014/12/08/code-executi...
- Gargyle 5y agoCan windows do per-user encryption?
- mtlynch 5y agoYes, EFS[0] works on a per-user basis. But it runs at the filesystem level and doesn't protect system binaries, so it's weaker than BitLocker, which encrypts the full volume and protects system binaries. [0] https://en.m.wikipedia.org/wiki/Encrypting_File_System https://en.m.wikipedia.org/wiki/Encrypting_File_System
- sandworm101 5y agoIf someone has this level of access and time with the device, implanting a bug and/or setting up a fake machine shouldn't be difficult. How many here would recognize that Evil Maid has swapped out your work machine with an identical model? It would be rigged to boot into an identical login screen and send your password back to the guy with the real laptop. That's what happens when everyone has the same shiny new machines (Apple). Give me a machine with a few scratches and custom boot screen.
- 5y ago
- dmurray 5y agoUnrolled: https://threadreaderapp.com/thread/1445020885472235524.html https://threadreaderapp.com/thread/1445020885472235524.html
- secondcoming 5y agoThanks. It's a pain to read a twitter thread with images without a twitter account. Their splashscreen covers all the images.
- llimos 5y agoDisabling cookies for twitter.com worked for me
- moviuro 5y agoThat's why you should also consider fancy nail polish an effective canary to evil maid attacks. https://www.computerweekly.com/blog/CW-Developer-Network/F-Secure-glams-up-laptop-security-with-glitter-nail-polish https://www.computerweekly.com/blog/CW-Developer-Network/F-S...
- tw04 5y agoIt’s an interesting thought experiment but not much else. Most of what he’s doing is predicated on the idea that any major CEO is walking around with a 7 year old laptop that is both well documented online and not configured with TPM + password which pretty much any competent IT department is going to require of an executive’s device.
- mattferderer 5y agoA lot of CEO's of small & medium size companies are the biggest hurdle for adding better security. I've unfortunately had access to a few CEO passwords & they've been embarrassingly bad. GSuite had (maybe still has) a tool for ranking password strength across your org. Used it once & sorted from weakest to strongest. My results were practically the org chart from top to bottom.
- mid-kid 5y agoI'm skeptical as to whether this can really be done in 10 mins. Finding the right chip can take a good while and especially tracing the bus you need to other chips. And the fact the traces were accessible with the thing semi-assembled is incredibly lucky, not to mention how he was able to find a "schematic" of the motherboard. I'd say an hour to pull this off is a minimum.
- 1MachineElf 5y agoI think the assumption with the 10min claim is that the attacker already knows the model of the laptop and has practiced this on identical ones. Possible if they've been on the CEO's tail for a long time.
- BeefWellington 5y agoIn a real-world scenario though, what system you're using would have been figured out and planned for ahead of time. If anything the example is arbitrarily harder rather than easier.
- 0xbadcafebee 5y agoPlease. Please. Twitter people, hear my plea. Twitter sucks ass and I don't want to scroll for a week to read your blog post. Please, please, just copy+paste it into a blog post and link to it on your Twitter. I swear I will "like & subscribe" to your Blog if you're worried about not getting enough eyeballs. I just do not want to ever have to look at Twitter.
- qualudeheart 5y agoI think Twitter should be replaced by Substack.
- coddle-hark 5y agoMeh, I disagree. I find most blog posts nowadays to be way too long. This Twitter thread is short and to the point.
- 0xbadcafebee 5y agoAll the more reason Twitter or somebody else should create a blog platform that encourages short, frequent blogs. Tweets get lost, they're usually meaningless, they aren't editable, you have to scroll through them, the comments aren't nested well, the URI is garbage, you can't group them by tags, etc. A blog could be designed to encourage abbreviated blog posts, and even help you split a post up for re-tweeting if you really wanted. Even auto-resize just to make it easier to see the entire thing in one page. Yet would retain all the great properties of legit blogs. You could call it "tldrblog".