3 ms·
Couldn't you have a small (meaning auditable) priviliged daemon store the keys in RAM when the keychain is unlocked once? The daemon would then release the keys
by captainmuon 3y ago
Couldn't you have a small (meaning auditable) priviliged daemon store the keys in RAM when the keychain is unlocked once? The daemon would then release the keys when it determines that the fingerprint is correct.
You would have to compare the fingerprints on the PC, or you would have to have a authenticated channel between the fingerprint reader and the PC, otherwise you would open yourself to device spoofing attacks. I think an attack like that was discovered recently for Windows notebooks.
This scheme would mean that root can access your keys without the fingerprint (unlike on a Mac I think), but the root account already has other ways to get your passwords.
Similar, you might be vulnerable against an attack where somebody confiscates your locked PC, freezes your RAM modules, and reads them out later. But you could encrypt the passwords in locked state using the TPM to make this much more difficult. And again, people who can do these attacks have much easier ways of getting your passwords, such as rootkits, or simply forcing you to put your finger on the sensor.
- mjg59 3y agoHow are the secrets kept secret? If the encryption key is stored on disk then giving me physical access lets me extract that and gain all the secrets. The TPM has no knowledge of the biometric state so doesn't help here.
- Sebb767 3y agoI think OP means that you enter your password to unencrypt your keyring once at boot or first use and then keep the keys in RAM. So you could not access the data when you steal the laptop while powered off, making it practically as safe as full-disk encryption.
- AgentME 3y agoThat would be as good as full-disk encryption, but it is possible and useful to do better than that with a TPM. With physical access to a running machine, it is possible to physically extract data from RAM. Law enforcement agencies even have hotplug devices that let them switch a running computer to battery power so they can seize it while keeping it on and do this.
- Sharlin 3y agoPerfect is the enemy of good, however.
- captainmuon 3y agoYes exactly. You'd enter your password once at boot. Then the OS remembers whatever key it needs to access your keychain. The OS becomes the arbitrator to allow who accesses the keychain. Similar to how BitLocker works, I assume. Windows has the keys to decrypt the hard disk, but it requires a valid login + the TPM to actually give it out. I'm not a crypographer so I won't claim to know details, but I think there are schemes to keep secrets safely encrypted in RAM, and only when the OS says OK it uses the TPM do decrypt the secrets. This fails of course when there is a bug in the OS, you can manipulate the CPU directly, or get between the CPU and the TPM, but then we are in "other side of the airtight hatchway" land anyway. I mean it is always a matter of what is my threat scenario, and what level of comfort do I want.