3 ms·
Why do you think those USB devices are "pretty likely"? In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2
by sweis 12y ago
Why do you think those USB devices are "pretty likely"?
In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_ant_catalog.pdf https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...
As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.
- mike_hearn 12y agoTXT doesn't rely on the LPC bus on modern motherboards because the TPM is integrated into the Northbridge. If any government agency can break TXT it'll be the NSA and I don't know if they are in the business of handing out their best exploits to random police teams at the moment.
- sweis 12y agoHow "modern" is modern? I understand there are some TPM implementations out there that are on-package, but there are still new servers being sold with TPM headers that I would expect to be easy to interpose. Regardless, this whole thing turned out to be a false alarm due to a KVM device being attached.