3 ms·
> The vulnerability also applies to other encryption systems using the TPM, like LUKS disk encryption. No, this is a Bitlocker problem. Systemd LUKS disk encry
by als0 3y ago
> The vulnerability also applies to other encryption systems using the TPM, like LUKS disk encryption.
No, this is a Bitlocker problem. Systemd LUKS disk encryption uses encryption on the bus by enabling TPM encrypted sessions: https://github.com/systemd/systemd/commit/acbb504eaf1be51572b1c0d0d490ac478bc41c64 https://github.com/systemd/systemd/commit/acbb504eaf1be51572...
- jeroenhd 3y agoI stand corrected, I'm glad systemd finally implemented encrypted TPM communication. I really don't understand why Microsoft is still allowing their keys to be MITM'd. I really should switch from Grub to systemd but the lack of boot time configuration (and, slightly less importantly, theming support) still makes me prefer Grub.
- snvzz 3y ago>I'm glad systemd finally implemented encrypted TPM communication. Note that, as far as I am aware, it never implemented unencrypted TPM communication. That's Microsoft-specific insanity.
- usr1106 3y agoMicrosoft implementation is vulnerable to eavesdropping as the submitted article shows. systemd would be vulnerable to MITM, but you don't MITM the SPI bus with some $100 hobbyist tooling.