5 ms·
"The BadRAM attack – which does require physical access to hardware" so...academically "blown wide open" but for anyone with a cogent opsec, probably not the e
by nimbius 2y ago
"The BadRAM attack – which does require physical access to hardware"
so...academically "blown wide open" but for anyone with a cogent opsec, probably not the end of the world.
- ngdasfwkj 2y agothe tee also "protects" parties trusted by the manufacturer from the owner
- astrange 2y agoThat is useful because many computers are portable which means they can be stolen.
- zb3 2y agoWell right, they can't be stolen from you because they were not yours to begin with :)
- zrm 2y agoSuppose that a portable computer uses full disk encryption. On boot it requires a long passphrase, or requires a short passphrase and connects to a remote server to supply a long decryption key but the remote server rate limits attempts. Either of these are rare because the system is normally on or in suspend rather than being cold booted, and once on the operating system rate limits local unlock attempts. What is the TEE supposed to buy you over this? Avoiding the negligible inconvenience of typing the long passphrase once a month if you don't have a remote server, which the enterprises that demand features like this would have? That seems like more of a solution in search of a problem and in any event not worth the cost in authoritarianism. Not only that, the TEE solution is less secure. If the device is stolen and you revoke access on the remote server then there is no way for an attacker with only the device to get the key. If the key is in a TPM on the device they can stick the device in a drawer and wait until someone finds a TPM vulnerability, then unlock it.
- astrange 2y agoA boot password + disk encryption helps but a) they can attack it before it reboots. b) most of the value is in the parts, so they don't need your data. You need to make the parts useless for repairs so it's not worth stealing it.
- zrm 2y ago> they can attack it before it reboots. But they can do that anyway? If they would guess your password or exploit your OS from the lock screen then they get access to your files even if the running OS is the one certified by the hardware. > most of the value is in the parts, so they don't need your data. You need to make the parts useless for repairs so it's not worth stealing it. Putting aside that "make the parts useless for repairs" is an obvious misfeature that will be used against you by the manufacturer, it's also orthogonal to boot loader signing etc. Making the parts "useless for repairs" would also be better achieved by making new and used repair parts available for competitive prices, driving down the cost of repairs to the point that stealing devices for repair parts isn't a lucrative endeavor. For example, make sure that traded-in devices never get crushed if they could be scavenged for parts to be sold into the repair market, providing a plentiful supply of used parts instead of making them scarce enough to be worth stealing.
- pclmulqdq 2y agoPhysical access is one of the things that a trusted execution environment is supposed to protect against. It's one of the major reasons to use a TEE instead of just normal VM isolation.
- londons_explore 2y agoIf I were holding billions of dollars of bitcoin keys for a darknet drug market, I would not trust a TEE... A TEE restricts attackers to nation-state and similar actors today, and is probably no hurdle at all in 5-10 yrs when some attack like this is published and the hardware is unpatchable.
- hedora 2y agoAcademics break TEE’s on a regular cadence. There’s this article, for example. A while back, there was clkscrew. I don’t get the impression these classes of attacks will ever be patchable.
- hulitu 2y ago> Physical access is one of the things that a trusted execution environment is supposed to protect against Is supposed to. Because money are sweet. Physical access means that you can exchange any part of your system and the bloody TEE would have no idea that it is MITM.
- fweimer 2y agoThe whole feature is advertised as something hypervisor operators can use to show customers that their data and code is safe from interference by these operators. Basically, it's about separating physical access to the hardware from access to the computation that occurs on the hardware, and the data that is processed there. This means that such attacks are relevant for once. I have my doubts whether this can ever work reliably. It seems risky to bet a lot of infrastructure investment on the fact that attacks like this one (or even better ones) do not happen. But the entire hypervisor business has the same structural problem (a bad CPU bug like the T-Head C910 vector issue could turn your hypervisor fleet into very expensive single-tenant machines over night), and yet here we are …
- cwillu 2y agoThe entire point is to protect against those (like the owner of the hardware) who have physical access.
- ls612 2y agoSo basically this is the best kind of vuln; not exploitable remotely, and unpatchable so you will always be able to get root on your own hardware.
- zokier 2y agoAMD has patches for all impacted platforms, and a method to verify that patch has been applied.
- cwillu 2y agoa method that can't be spoofed though?
- whaleofatw2022 2y agoTAO tho...
- numpad0 2y agoI think this type of implements are also used to make payments work on devices, in addition to enabling DRM.
- zb3 2y agoIn that case it doesn't seem it's really the "owner" of that hardware..
- dmkolobov 2y agoThe operators own the hardware and lease it to customers for computation. Those customers do not trust the operators to not peek at their Super Sensitive Data. TEE is a way for the operator to provide assurances to their customers that they will not, and more importantly cannot, exfiltrate customer data. This is in theory. In practice, as demonstrated by the article, these assurances are not bulletproof.
- avhon1 2y ago> In some cases, with certain DIMM models that don't adequately lock down the chip, the modification can likely be done through software. So on some systems, the hack could be performed entirely remotely.
- kcb 2y agoThe whole purpose of TEEs and confidential computing is to prevent the people with your server from seeing what you're doing on it.
- lksaar 2y agoThis is somewhat relevant for DRM. All those downloads from netflix/prime/disney plus depend on breaking into a TEE and retrieving decryption keys.
- EPWN3D 2y agoIn modern threat models, this is a malicious insider and hardly some exotic circumstance. If you're running a data center in an authoritarian country, you probably care.
- hulitu 2y ago> If you're running a data center in an authoritarian country, you probably care. You should care also about democratic countries. For your own good.