6 ms·
Show HN: ssh-tpm-agent – SSH agent for TPMs
- lathiat 3y agoThis is a great idea. I now exclusively use SSH keys on hardware security modules of some kind. I use "Secretive", a mac app that does the same, plus a yubikey using yubikey-agent (https://github.com/FiloSottile/yubikey-agent https://github.com/FiloSottile/yubikey-agent; there are too many complicated ways to use SSH keys with a yubikey this is one of the friendliest ones). Depending on the security and frequency of which I access the service impacts whether I need presence confirmation or use secretive versus the yubikey. I would be remiss to mention there are existing SSH TPM projects, not sure how this one differentiates. It seems to at least have the user experience pretty simple, similar to yubikey-agent (and secretive), and unlike some of the existing solutions which have quite a few extra steps: https://github.com/tpm2-software/tpm2-pkcs11/blob/master/docs/SSH.md https://github.com/tpm2-software/tpm2-pkcs11/blob/master/doc... I really love it when projects like this address there are "competitors" or other software in the space and provide a fair comparison. It would be great to see one of those here :) For example you can easily use SSH FIDO keys but they aren't supported by all server sides, ECDSA keys often are (though not always!) etc :)
- linsomniac 3y agoThe ; got included in the yubikey-agent URL: https://github.com/FiloSottile/yubikey-agent https://github.com/FiloSottile/yubikey-agent Thanks for those pointers!
- Foxboron 3y agoIt's not written in the README.md, but `ssh-tpm-agent` is very much a copy-paste of `yubikey-agent` but with a bit better testing and the yubikey part swapped with TPM stuff.
- zhfliz 3y agohave you considered using ykcs11? ykcs11 allows you to use the native SSH agent (or even no agent at all for individual ssh invocations) with an ssh key on a yubikey using their pkcs11 provider. https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PKCS11.html https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PK...
- Foxboron 3y agoWhen you see a guide containing a 7 step manual to do something that should be simple, it's worth taking a step back and consider the question if you can make this valueable security feature more easily accessible. Side-loading so-names into your security critical apps is probably something you should be more critical of as well.
- zhfliz 3y agoare you extending this to the usage of yubikey-agent and ssh-tpm-agent as well? both variants, whether it's using a PKCS11 provider using a standardized interface, or using a completely custom SSH agent, will need to deal with secret material. although I'm no expert on the inner workings of SSH, I'd expect there to not be much difference between having the OpenSSH agent interface with ykcs11 (which is also open source and can be reviewed) and using an alternative agent with piv capabilities that was found on github.
- Foxboron 3y ago> are you extending this to the usage of yubikey-agent and ssh-tpm-agent as well? No, as they never get loaded into the ssh binary and are external programs communicating over an interface. Consider reading over the recent qualys vulnerability report on how messy this dloading of pkcs11 actually is. https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh... >both variants, whether it's using a PKCS11 provider using a standardized interface, or using a completely custom SSH agent, will need to deal with secret material. `ssh-tpm-agent` is not dealing with secret material. That is delegated to the TPM and we are only in the business of telling the TPM to sign stuff for us. Yubikey-agent does create a private key on the machine before inserting it into the yubikey. I would not call these two things equal and there are a difference to what the potential impact is. >although I'm no expert on the inner workings of SSH, I'd expect there to not be much difference between having the OpenSSH agent interface with ykcs11 (which is also open source and can be reviewed) and using an alternative agent with piv capabilities that was found on github. There is a separation of concerns here though.
- anotherhue 3y agoThis looks great. I was using GPG's ssh agent functionality with 'keytotpm' but this is cleaner.
- osy 3y agoWhat’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized privileged access anywhere so it’s a very small area of the Venn diagram where you have an attacker whose capability is “physical access” but also “does not possess any exploit or one-touch-access”. This narrows down the list to: • Malicious coworkers, family members, and house keepers against a computer who is NEVER left unattended (i.e. screen locked when you leave 100% of the time) • Local government agents (i.e. the local police) who can confiscate your powered on device but cannot afford to buy 3rd party cracking services that utilize exploits or more advanced extraction techniques (external RAM dumping) • A device that is completely powered off and confiscated by a powerful nation state agent but not later on returned to the original owner and they forgot to wipe the device in case of implants. In any case the design of TPM is completely flawed and suffers from “astronaut architects”. If you grep the three volume 1000+ pages of the TPM 2.0 architecture documents, you’ll not find a single mention of “threat model”. Specifically TPM is a multi-million dollar industry signed on by many tech companies (including Microsoft who uses it as an excuse to get you to buy a new PC because TPM == more secure right, but also because older computers don’t support it) because places like governments and banks require it because they also don’t understand threat models. TPM protection is fundamentally flawed because: • It cannot protect against a compromise in the boot chain (e.g. a UEFI driver is exploited, and it lies to TPM about the subsequent stage of code that is loaded while running a malware implant) • It cannot protect against RCE (remote code execution). This means if Windows ever has a vulnerability that can be exploited remotely, they can keylog -> steal your PIN -> replay it later to dump the key. Or just dump the key in memory if they have a PE (privilege escalation) as well. • It cannot protect against a user volunteerly installing malware (Bonzi buddy?) • It cannot protect against an attacker who installs something on your unattended computer (USB Rubber Ducky, Flipper Zero, etc) Basically the most common ways people get compromised sees no protection from TPM while esoteric attack situations that no attacker will realistic attempt are protected. TPM can never protect against these cases because it is logically (fTPM) and/or physically (dTPM) separate from the CPU. That means it cannot perform any policy enforcement against a CPU whose execution is under control of the attacker.
- lathiat 3y ago
- elric 3y agoHow many keys can I store inside a laptop's TPM? Is there a limit? I have hundreds of SSH key pairs, one for each thing I connect to. My .ssh/config file defaults to a nonexistent key for all hosts, except for hosts configured elsewhere in the file, where each host gets its own IdentityFile entry.
- Foxboron 3y agoIt has 6.3 Kb or something of memory. So not a lot. What `ssh-tpm-agent` does is that it simply doesn't store the keys on the TPM at all. It creates the ephemeral SRK, then load a sealed private key back into the TPM that allows us to use it. So you can have a couple hundred SSH key pair this way.
- sneak 3y agoWhat is your threat model that requires such complexity?
- deleted 3y ago[deleted]
- elric 3y agoIt's not terribly complex, and it's all scripted. I don't like my identity being trackable across services, or across areas of my life. For instance, dickheads have created databases of public keys scraped from services like github, which can be used to identify the vast majority of github users whenever they ssh into some other service. By default, the ssh client will try to authenticate with every available keypair until it finds a match, which can further leak information about you(r machine).
- sneak 3y agoYes, I understand the attack, but what is the threat? You are already uniquely identifying yourself to each of these servers. What is the threat to you if your identity is correlated between them? You probably have the same username on many of them, no? It seems like privacy cosplay to me, tbh. I'm genuinely curious what type of threat it actually protects against, if any. What happens when two different systems you ssh into knows it's elric on both?
- s09dfhks 3y agoAt first I was expecting this to be a joke repo for “technical program managers”. Was hoping it’d just print “connected to $1”
- intelVISA 3y agoThat sorta TPM does wealth extraction, this sorta TPM protects data extraction. Both are frequently mandated and provide heavy lock-in so YMMV.
- cryptonector 3y agoThe idea is awesome. I'm going to have to try it out. It'd be cool if ssh-keysign could use this agent!
- Foxboron 3y agoApparently you can use a ssh-agent for HostKeys, and by extension ssh-keysign. So I think this should be trivial to implement actually. It might be cool to add some attestation feature so you can verify the boot of the machine before releasing the host keys. Might be practical in scenarios where you are SSHing into an initrd or a sensitive remote host.