4 ms·
> These were prone to (relatively primitive) bus sniffing attacks, where you would hook up a Logic Analyzer to the bus, watch a regular boot procedure grab the
by als0 3y ago
> These were prone to (relatively primitive) bus sniffing attacks, where you would hook up a Logic Analyzer to the bus, watch a regular boot procedure grab the disk key, and then use software like Dislocker to extract all data from a USB Live Linux or alike.
The TPM supports encrypted sessions, but they are opt in. See Parameter Encryption in the TPM spec. The issue is that Bitlocker doesn't use them for whatever reason. If Bitlocker turned on encrypted sessions, it would be not possible to sniff the key. It's crazy that Microsoft keep things insecure.
- hnj2 3y agoWe haven't looked to much into encrypted sessions, but for anyone wondering how they prevent MITM attacks in such a scenario: systemd-cryptenroll seems to be ahead in this regard: https://github.com/systemd/systemd/commit/acbb504eaf1be51572b1c0d0d490ac478bc41c64 https://github.com/systemd/systemd/commit/acbb504eaf1be51572...