3 ms·
Please note, though, that's imperative to then go for a BitLocker TPM+PIN configuration at least. A standalone (discrete) TPM with TPM-only protectors can be at
by cwerling 3y ago
Please note, though, that's imperative to then go for a BitLocker TPM+PIN configuration at least. A standalone (discrete) TPM with TPM-only protectors can be attacked by bus sniffing, a hardware attack much simpler than ours. [1]
The beauty of a discrete TPM is its anti-hammering protection, making a numerical PIN a very effective security measure (akin to a SIM/SmartCard).
[1] https://www.sciencedirect.com/science/article/pii/S0898122112004634?via%3Dihub https://www.sciencedirect.com/science/article/pii/S089812211...
- als0 3y agoBus sniffing can be mitigated by encrypting communications using the TPM's in-built parameter encryption capabilities.
- cryptonector 3y agoYes, this. Bitlocker could absolutely do this. There's still other active attacks resulting from the BMC and BIOS and parts of the OS not also doing the encrypted session thing.