10 ms·
Any thread model should take firmware into account. There have been examples of unauthenticated remote code execution against Intel ME[0]. This isn't theoretica
by c4mpute 3y ago
Any thread model should take firmware into account. There have been examples of unauthenticated remote code execution against Intel ME[0]. This isn't theoretical, this isn't an assumption, this has happened. Those exploits are independent of the OS running, with certain configurations the system doesn't even need to be switched on, just plugged in. With fTPM as an ME module (not all fTPMs are such) this provides an additional huge attack surface.
[0] https://mjg59.dreamwidth.org/48429.html https://mjg59.dreamwidth.org/48429.html
- mjg59 3y agoThat vulnerability allowed unauthenticated access to AMT, not arbitrary code execution on the ME. I agree that an ME-based fTPM has a larger attack surface than a dTPM, but we haven't seen many cases where that's had real-world poor outcomes.