6 ms·
What’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized priv
by osy 3y ago
What’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized privileged access anywhere so it’s a very small area of the Venn diagram where you have an attacker whose capability is “physical access” but also “does not possess any exploit or one-touch-access”. This narrows down the list to:
• Malicious coworkers, family members, and house keepers against a computer who is NEVER left unattended (i.e. screen locked when you leave 100% of the time)
• Local government agents (i.e. the local police) who can confiscate your powered on device but cannot afford to buy 3rd party cracking services that utilize exploits or more advanced extraction techniques (external RAM dumping)
• A device that is completely powered off and confiscated by a powerful nation state agent but not later on returned to the original owner and they forgot to wipe the device in case of implants.
In any case the design of TPM is completely flawed and suffers from “astronaut architects”. If you grep the three volume 1000+ pages of the TPM 2.0 architecture documents, you’ll not find a single mention of “threat model”.
Specifically TPM is a multi-million dollar industry signed on by many tech companies (including Microsoft who uses it as an excuse to get you to buy a new PC because TPM == more secure right, but also because older computers don’t support it) because places like governments and banks require it because they also don’t understand threat models.
TPM protection is fundamentally flawed because:
• It cannot protect against a compromise in the boot chain (e.g. a UEFI driver is exploited, and it lies to TPM about the subsequent stage of code that is loaded while running a malware implant)
• It cannot protect against RCE (remote code execution). This means if Windows ever has a vulnerability that can be exploited remotely, they can keylog -> steal your PIN -> replay it later to dump the key. Or just dump the key in memory if they have a PE (privilege escalation) as well.
• It cannot protect against a user volunteerly installing malware (Bonzi buddy?)
• It cannot protect against an attacker who installs something on your unattended computer (USB Rubber Ducky, Flipper Zero, etc)
Basically the most common ways people get compromised sees no protection from TPM while esoteric attack situations that no attacker will realistic attempt are protected.
TPM can never protect against these cases because it is logically (fTPM) and/or physically (dTPM) separate from the CPU. That means it cannot perform any policy enforcement against a CPU whose execution is under control of the attacker.
- lathiat 3y agoIt means malware can’t exfiltrate the SSH key from your machine and keep using it. But yes they can potentially use it while still on your machine depending on if presence confirmation or re-inputting a credential is required. But that still closes a big gap. On a Mac secretive can also pop a notification making it more likely to passively observe such usage (not fool proof though) and the key can’t (easily, maybe with some complex exploit) be used from an app not signed by the original developer. It can also require re input of your password. That specific security probably isn’t possible on Linux though.
- candiddevmike 3y ago> It means malware can’t exfiltrate the SSH key from your machine and keep using it Are you sure about that? Presumably the secret parts of the SSH key are being read into memory at some point, or a RCE could dump the key the same way ssh-tpm-agent does. Don't rely on a TPM to store secrets. Use a secrets store that can be audited for use and have it generate dynamic, short lived credentials. For SSH, use SSH CAs.
- Foxboron 3y ago>Are you sure about that? Presumably the secret parts of the SSH key are being read into memory at some point, or a RCE could dump the key the same way ssh-tpm-agent does. This is not how ssh-tpm-agent works. It does the key signing inside the TPM so you do not have access to the key on the machine itself. The private key never hits memory or the machine itself.
- alex7734 3y agoTPM is not designed to prevent intrusion from hackers, it's designed to turn your general purpose computer into an appliance by preventing you, the owner, from modifying the OS in your computer as you see fit (and interact with third party services at the same time, thanks to remote attestation). It means that instead of _just patching_ the software in your computer to customize it now you have to resort to using 0days to do it like a criminal which makes it considerably harder. It does help against hackers, of course, and the same restrictions do secure you against some attacks (evil maid attacks) but that's not the intent. The threat model TPM protects against is: - You log in into Netflix (or whatever) - Netflix sends your PC the movie so you can watch it. - Your PC now has the movie in memory. - You extract the movie from your PC's memory and you can now watch it forever without Netflix's permission. What the "trusted" in Trusted Platform Module means is that with TPM they can trust your PC to not let you do that.