Lee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year agoBitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPMwww.tomshardware.comexternal-linkmessage-square96fedilinkarrow-up1752arrow-down118
arrow-up1734arrow-down1external-linkBitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPMwww.tomshardware.comLee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year agomessage-square96fedilink
minus-squarefmstrat@lemmy.nowsci.comlinkfedilinkEnglisharrow-up35arrow-down4·1 year agoSay it with me now: LUUUUUKS
minus-squarebaseless_discourse@mander.xyzlinkfedilinkEnglisharrow-up34·edit-24 months agodeleted by creator
minus-squarePhoenixz@lemmy.calinkfedilinkEnglisharrow-up15·1 year ago CPU communicates with TPM in plaintext Because of course
minus-squareEufalconimorph@discuss.tchncs.delinkfedilinkEnglisharrow-up6·1 year agoCPU doesn’t have any secure storage, so it can’t encrypt or authenticate comms to the TPM. The on-CPU fTPMs are the solution, the CPU then has the secure storage.
minus-squarebaseless_discourse@mander.xyzlinkfedilinkEnglisharrow-up2·edit-24 months agodeleted by creator
minus-squarebaseless_discourse@mander.xyzlinkfedilinkEnglisharrow-up1·edit-24 months agodeleted by creator
minus-squareHelloHotel@lemm.eelinkfedilinkEnglisharrow-up15·edit-21 year agoI wondered why LUUUUUKS didnt use the TPM, why do i have to put my password in… this is absolutely why. Edit: fixed spelling of LUUUUUKS
minus-squarecooopsspace@infosec.publinkfedilinkEnglisharrow-up4·edit-21 year agoAlso yes you can, I wouldn’t recommend it though. Maybe in addition to your password though. Wait until you see Dracut and Tang.
minus-squaremlaga97@lemmy.mlaga97.spacelinkfedilinkEnglisharrow-up3·1 year agoWhat exactly is the point of full disk encryption if the system auto-unlocks on boot?
minus-squarerambling_lunatic@sh.itjust.workslinkfedilinkEnglisharrow-up1·1 year agoProtection against tampering, maybe? Bad excuse, but that is the logic I’ve heard.
Say it with me now: LUUUUUKS
deleted by creator
Because of course
CPU doesn’t have any secure storage, so it can’t encrypt or authenticate comms to the TPM. The on-CPU fTPMs are the solution, the CPU then has the secure storage.
deleted by creator
deleted by creator
I wondered why LUUUUUKS didnt use the TPM, why do i have to put my password in… this is absolutely why.
Edit: fixed spelling of LUUUUUKS
Also yes you can, I wouldn’t recommend it though. Maybe in addition to your password though.
Wait until you see Dracut and Tang.
What exactly is the point of full disk encryption if the system auto-unlocks on boot?
Protection against tampering, maybe?
Bad excuse, but that is the logic I’ve heard.