5 ms·
We shouldn't. TPM-based security is only sufficient against unsophisticated attackers such as a common thief stealing your laptop from your backpack.
by isilofi 3y ago
We shouldn't. TPM-based security is only sufficient against unsophisticated attackers such as a common thief stealing your laptop from your backpack.
- jon-wood 3y agoThis is a massive overstatement of the situation. Sure, a TPM might not protect you against the NSA or the Chinese government stealing your computer. If configured correctly it probably will protect you against anything less than a major nation state stealing your computer.
- justaj 3y agoBut wouldn't a properly configured LUKS encryption protect against nation-state threats too? If so, then why still use TPM?
- lostmsu 3y agoIf machine is not attached to a terminal it is useful if it boots on its own.
- immibis 3y agoThen it still boots on its own if the bad guy has it.
- alufers 3y agoConvenience, faster boot. Or if you have a headless server with disk encryption, but you want it to come back online without intervention after a reboot or power failure. It's all trade-offs.
- SV_BubbleTime 3y agoIn the scenario of headless, if I’m not missing something this only prevents drives from walking off. If the whole machine walks off you are in just as much trouble as not being encrypted at all if you don’t really trust your OS permissions systems?
- Nextgrid 3y agoThe whole machine walking off is more detectable though. You can use TPM as one factor (among many, such as the presence of the machine on the expected network and no unexpected downtimes) to obtain storage keys from a separate trusted server, using TPM remote attestation to assert the machine hasn't been tampered with in-place (by merely booting it off a compromised OS). The separate authentication server can be configured to only hand out the storage encryption key on expected reboots, so if the machine unexpectedly walks off and then powers back on that server would refuse to hand out the key, thus the stolen machine is now useless.
- Asmod4n 3y agoWhen someone steals your device and try’s to guess a user password a tpm can just throw away it's keys. (Or something similar) Try it on a secure boot and tpm2 enabled Bitlocker encrypted drive, the only way to get in is via the recovery key after a configurable number of attempts.
- alufers 3y agoIf you take some basic precautions - disable interrupting the boot process, serial console, etc. then bypassing that requires significant effort. As an attacker you need to know the versions of the software working on the server, know some exploit and then have the experise to use it. For example I know that the police in my country use off the shelf disk cloning devices and then some basic forensics software for analyzing the disk image. This can be done by an average computer technician, and such a TPM scheme would totally prevent them from extracting data. Of course for bigger cases they can invest some more effort, but they would have to be sure that there is some important data there to justify the cost.
- jon-wood 3y agoTPM based encryption is hugely useful in embedded devices, where you really don’t want to have to despatch someone to type the passphrase in. By driving it via the TPM you’re protected against someone removing the storage and being able to read the decryption key off it, and you’re also protected against someone modifying the components required to get to a decrypted disk to inject code you weren’t expecting - if the kernel or bootloader is modified then the device simply won’t boot.
- pmontra 3y agoWith an embedded device isn't easier to just steal the device instead of only the storage and making the device useless anyway?
- bmicraft 3y agoIn this scenario protecting the secrets on the device is supposedly more important that the monetary value of the device itself.
- SV_BubbleTime 3y agoI sell a device. There are lots of them in hands. You still aren’t getting my device key off of it. Yes, you can use that device all you like, but you aren’t going to clone it and make more.
- sillystuff 3y agoYou've described DRM; this is exactly why a lot of people are wary of TPMs.
- lxgr 3y agoNo, DRM is safeguarding other people's keys on your device. There's more applications of trusted computing and TPMs than that; one of them is using it to safeguard your own keys.
- cyberax 3y agoYes, but you'll need to enter a long password on every boot.
- goodpoint 3y agoNo, it's worse. It's *making* you vulnerable to those actors and possibly more.
- Nextgrid 3y agoThe majority of people don't want to type a long passphrase every boot (or would pick a trivially-bruteforceable one) and FDE-backed TPM (even if vulnerable to state-sponsored attacks) is better than what it would otherwise be which is no FDE at all.
- mjg59 3y agoEh no that's not true. If a device uses a discrete TPM and isn't using authenticated sessions it's trivial to sniff the bus and extract the encryption key. If it is then it's less trivial because you need to interpose the TPM but that's still in "Can solder SMT parts" territory, not major nation state.
- Bognar 3y agoYou can only extract the encryption key if using the unencrypted APIs. You can establish and require an encrypted channel with the TPM if you know which TPM you are expecting.
- goodpoint 3y agoNot even that.