4 ms·
This is highly misleading. fTPM is more secure against _this_ kind of attack, with physical access to the bus wires. However, since fTPM is a Firmware-TPM, it
by c4mpute 3y ago
This is highly misleading.
fTPM is more secure against _this_ kind of attack, with physical access to the bus wires. However, since fTPM is a Firmware-TPM, it is vulnerable to all kinds of attacks on the system's firmware, even remotely, even via the network, even maybe if the computer is switched off. Remember all those (even unauthenticated, remote) XML-parser exploits in the Intel ME? fTPM is just one more ME module, and of course vulnerable to those exploits.
So overall, I consider fTPM a huge step back, because you might even get access without physical presence. For an fTPM, attack surface is far larger (because all of the ME software), minimum attack complexity may be smaller (because there will one day be a metasploit module for all those software problems, whereas HW hacking is always a certain hurdle), required attacker privileges are less (prolonged unobserved physical presence vs. network). Thus objectively worse in all aspects.
What would be better would be a dTPM that is integrated e.g. into a SoC, such that there are no exposed wires anywhere without decapping the SoC. Some systems such as phones work like that, but this is hard to tell even from the technical specs.
- FirmwareBurner 3y ago>fTPM is more secure against _this_ kind of attack, with physical access to the bus wires. However, since fTPM is a Firmware-TPM, it is vulnerable to all kinds of attacks on the system's firmware, even remotely Yes, fTPM is more vulnerable in theory to remote attacks, but fTPM could always be patched, while it's more difficult to de-solder the TPM chip off your motherboard and replace with a non-vulnerable one and there are vulnerable dTPM chips out there. Both solutions have their own pros and cons you have to weigh in the context of cost, convenience and threat model. >What would be better would be a dTPM that is integrated e.g. into a SoC Isn't that what fTPM is? The TPM spec firmware runs on the security microcontroller (Intel PTT and AMD PSP) built in the same SoC as the CPU. What would be better is having the TPM be removable from the machine, like the YubiKey. Currently, dTPM and fTPM are basically like having your YubiKey always plugged in and glued to your machine. Convenient for authenticating you, but not secure from guys stealing your machine and probing it in a lab.
- auguzanellato 3y ago> but fTPM could always be patched dTPMs can also be patched, the TPM in my Dell laptop is discovered by fwupd as being updatable.
- Guvante 3y agoWhat threat model assumes it is easier to attack fTPM than the OS that is running? Once you are online Bitlocker does nothing and you can just attack the OS and bypass all of its protections trivially... Your threat model here assumes arbitrary code execution as a starting point of an exploit, the security game is up for the PC once that occurs.
- c4mpute 3y agoAny thread model should take firmware into account. There have been examples of unauthenticated remote code execution against Intel ME[0]. This isn't theoretical, this isn't an assumption, this has happened. Those exploits are independent of the OS running, with certain configurations the system doesn't even need to be switched on, just plugged in. With fTPM as an ME module (not all fTPMs are such) this provides an additional huge attack surface. [0] https://mjg59.dreamwidth.org/48429.html https://mjg59.dreamwidth.org/48429.html
- mjg59 3y agoThat vulnerability allowed unauthenticated access to AMT, not arbitrary code execution on the ME. I agree that an ME-based fTPM has a larger attack surface than a dTPM, but we haven't seen many cases where that's had real-world poor outcomes.
- etna_ramequin 3y ago> What would be better would be a dTPM that is integrated e.g. into a SoC, such that there are no exposed wires anywhere without decapping the SoC. Some systems such as phones work like that, but this is hard to tell even from the technical specs. That’s Microsoft’s Proton chip, I believe.
- mjg59 3y agoPluton rather than Proton, but yes.
- etna_ramequin 3y agoYes, that’s right, thanks!
- withinboredom 3y agoI was always under the impression that once an attacker got physical access: all bets were off. Literally anything is possible at that point.