4 ms·
`tpm2-totp` defeats the entire "replace the laptop" threat scenario. https://github.com/tpm2-software/tpm2-totp https://github.com/tpm2-software/tpm2-totp
by Foxboron 2y ago
`tpm2-totp` defeats the entire "replace the laptop" threat scenario.
https://github.com/tpm2-software/tpm2-totp https://github.com/tpm2-software/tpm2-totp
- blueflow 2y agoThe "replaced laptop" scenario is a full MITM on the hardware. TOTP generally does not protect against MITM. The required TOTP code is, in this scenario, generated by the device in the attackers hand. So the fake could also display it.
- Foxboron 2y agoYou need to decide between the attack here. Are you subverting hardware or are you replacing a laptop? The TOTP token here is sealed inside TPM.
- blueflow 2y agoAnd what do you need to do to unseal it? And why cant the fake laptop relay that to the real laptop?
- Foxboron 2y agoIt's never unsealed. `tpm2-totp` does an encrypted session to the TPM and runs `TPM2_HMAC` on the TPM shielded key, you can also include PCRs to add further authentication to this entire exchange. What do you mean with "relay"? (All of this is trivially solved with glitter nail polish anyway.)
- blueflow 2y agoYes and you can relay that authentication, too. The same way the fake laptop can relay your password to me, i could also relay the generated TOTP code from the stolen laptop to the fake in front of you. As tried to convey, the fake laptop is basically a full MITM on your screen/keyboard. Making a machine visuals non-reproducible helps that, but only if the attacker cannot easily switch the exterior parts (chassis, keyboard) between the two machines.
- Foxboron 2y ago> The same way the fake laptop can relay your password to me, i could also relay the generated TOTP code from the stolen laptop to the fake in front of you. Also any authentication to generate that TOTP in the first place. As tried to convey, the fake laptop is basically a full MITM on your screen/keyboard. This is a hollywood level threat scenario. It involves the attacker having intimate familiarity with the operating system, and having to break inn twice to even get this attack done. If you do put inn the effort then I deserve to be hacked and can pick up sheep farming in the country side.
- blueflow 2y agoWhy twice? You can keep the fake laptop. The OS does not matter? Grab the video output via HDMI/DisplayPort and insert the keypresses via USB. Thats likely gonna work. Basically what modern KVM switches do. And setup the fake laptop as VNC client. Same tech that companies can use to remotely manage servers.
- Foxboron 2y ago> The OS does not matter? Of course it does. You are replaying the logos and screens. > Grab the video output via HDMI/DisplayPort and insert the keypresses via USB. Thats likely gonna work. Basically what modern KVM switches do. And setup the fake laptop as VNC client. Same tech that companies can use to remotely manage servers. You believe you can boot up an entire VNC client to display something that would take most machines under a second to display?
- blueflow 2y ago> You are replaying the logos and screens Which the real machine happily gives me via HDMI/DisplayPort. > You believe you can boot up an entire VNC client to display something that would take most machines under a second to display? Do i need to? That the user presses the power button does not mean the machine will freshly boot. It could also be an unsuspend/wakeup or some regular ACPI event if the machine is only appearing to be off.