From: Duboucher Thomas <thomas@duboucher.eu>
To: The development of GRUB 2 <grub-devel@gnu.org>
Subject: Re: TPM support status ?
Date: Wed, 19 Aug 2009 22:13:43 +0200 [thread overview]
Message-ID: <4A8C5CF7.9090408@duboucher.eu> (raw)
In-Reply-To: <d7ead6de0908191228g7f1d30f7m474301616fe8539b@mail.gmail.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Vladimir 'phcoder' Serbinenko a écrit :
> Could you please avoid using abbreviations. It's already hard to read
> TPM specs because of their twisted terminology. If EKP is the key
> stored in the TPM then manufacturer can keep a copy of public or
> private key and nobody will notice.
Sorry for the abbreviations. :|
According to the specs, the private endorsement key must not come out of
the TPM. Also, the pair has to be signed by the "manufacturer". If the
manufacturer is not trutworthy, he can squirt the keys and then have a
local copy of the pair. However, it's no use keeping this key since its
only use is to generate AIK (one-time key pairs that are used to
comunicate using HMAC).
>>>> Also, most of the time, the reset operation is disabled by the TPME.
>>> This is a problem (again): you can't make TPM to behave like you want.
>> Yep, but why would you allow reseting the EKP? You can reset everything
>> else because you may need to, but it's no use reseting the EKP.
>>
> By using this key you can prove manufacturer that you use the key he
> burned in device it controls which opens the bad doors.
Well, like in any security system, you suppose the system itself is
secure ... which is not always the case, intentionnaly or not.
>>>> It _can't_ be used for other operations iirc.
>>> Checking you use windows?
>> Not the TPM, only a ***** BIOS and a ***** manufacturer (which can base
>> their scheme on TPM). We saw this in the past, but we didn't needed a
>> TPM for that, only human mind. :|
> But TPM is designed to prevent BIOS modifications.
It's not against my words. I was telling that a malicious manufacturer
can use a TPM to build a system where the BIOS is less likely to be
modified. And if on top of this he uses this to protect the operating
system ... These are use cases of TPM that _we_ don't want to see.
> If you have tokens why do you care if attacker has your passphrase.
> And just the keyboard input can contain a lot of valuable data itself.
> Why do you suppose that attacker can stole the laptop but not the token?
I'm not making any supposition, I'm making all of them. And I'm trying
to reduce the different schemes an attacker could use. There is _always_
a way to steal the secret. At least let's make it less likely to happen.
>> Don't you think it isn't even worth working on?
> If not the freedom concerns it could be fun coding. But IF.
Let's hope that those who works on it are concerned, but you'll always
find someone who isn't.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iEYEARECAAYFAkqMXPcACgkQBV7eXqefhqhyFACeNEV9eGIX8Dv+Me0h166yRdg4
uDYAoKLBpliNkKionXrBIOqzu+N7e/rG
=eOtB
-----END PGP SIGNATURE-----
next prev parent reply other threads:[~2009-08-19 20:14 UTC|newest]
Thread overview: 83+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-19 11:00 TPM support status ? Emmanuel Fleury
2009-08-19 11:51 ` Vladimir 'phcoder' Serbinenko
2009-08-19 12:25 ` Michael Gorven
2009-08-19 12:42 ` Vladimir 'phcoder' Serbinenko
2009-08-19 13:24 ` Michael Gorven
2009-08-19 13:48 ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:49 ` Michael Gorven
2009-08-19 20:13 ` Vladimir 'phcoder' Serbinenko
2009-08-19 14:01 ` Robert Millan
2009-08-19 19:53 ` Michael Gorven
2009-08-19 20:15 ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:17 ` Robert Millan
2009-08-19 14:10 ` Robert Millan
2009-08-19 15:44 ` Isaac Dupree
2009-08-19 17:20 ` Vladimir 'phcoder' Serbinenko
2009-08-19 17:25 ` Duboucher Thomas
2009-08-19 17:39 ` Isaac Dupree
2009-08-19 18:01 ` Vladimir 'phcoder' Serbinenko
2009-08-19 18:36 ` Duboucher Thomas
2009-08-19 18:48 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:13 ` Michael Gorven
2009-08-19 20:25 ` Vladimir 'phcoder' Serbinenko
2009-08-20 7:38 ` Michael Gorven
2009-08-20 10:15 ` Vladimir 'phcoder' Serbinenko
2009-08-20 10:22 ` Michael Gorven
2009-08-20 10:29 ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:36 ` Duboucher Thomas
2009-08-19 20:03 ` Michael Gorven
2009-08-19 20:18 ` Vladimir 'phcoder' Serbinenko
2009-08-19 14:42 ` Robert Millan
2009-08-19 20:16 ` Michael Gorven
2009-08-19 20:27 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:33 ` Michael Gorven
2009-08-19 20:34 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:45 ` Duboucher Thomas
2009-08-20 16:09 ` Robert Millan
2009-08-20 16:17 ` Michael Gorven
2009-08-20 16:13 ` Robert Millan
2009-08-19 14:34 ` Robert Millan
2009-08-19 16:33 ` Duboucher Thomas
2009-08-19 17:04 ` Vladimir 'phcoder' Serbinenko
2009-08-19 18:13 ` Duboucher Thomas
2009-08-19 18:37 ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:16 ` Duboucher Thomas
2009-08-19 19:28 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:13 ` Duboucher Thomas [this message]
2009-08-19 20:22 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:37 ` Duboucher Thomas
2009-08-19 20:42 ` Michal Suchanek
2009-08-19 20:57 ` Duboucher Thomas
2009-08-19 21:00 ` Vladimir 'phcoder' Serbinenko
2009-08-19 21:07 ` Duboucher Thomas
2009-08-19 23:39 ` Michal Suchanek
2009-08-19 20:44 ` Vladimir 'phcoder' Serbinenko
2009-08-20 7:40 ` Michael Gorven
2009-08-20 10:19 ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:21 ` Michal Suchanek
2009-08-20 7:41 ` Michael Gorven
2009-08-20 7:49 ` Michal Suchanek
2009-08-20 7:52 ` Michael Gorven
2009-08-20 7:59 ` Michal Suchanek
2009-08-20 8:07 ` Michael Gorven
2009-08-20 8:20 ` Michal Suchanek
2009-08-20 8:33 ` Michael Gorven
2009-08-20 10:21 ` Vladimir 'phcoder' Serbinenko
2009-08-20 10:58 ` Michal Suchanek
2009-08-20 11:15 ` Michael Gorven
2009-08-20 11:24 ` Vladimir 'phcoder' Serbinenko
2009-08-20 11:38 ` Michal Suchanek
2009-08-20 13:06 ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:31 ` Duboucher Thomas
2009-08-20 17:47 ` about smartcards (Re: TPM support status ?) Robert Millan
2009-08-20 18:35 ` decoder
2009-08-20 19:48 ` Vladimir 'phcoder' Serbinenko
2009-08-20 20:02 ` Robert Millan
2009-08-20 20:11 ` decoder
2009-08-20 20:24 ` Vladimir 'phcoder' Serbinenko
2009-08-20 20:30 ` Robert Millan
2009-08-20 20:16 ` TPM support status ? Vladimir 'phcoder' Serbinenko
2009-08-20 17:50 ` Duboucher Thomas
2009-08-21 11:42 ` Michal Suchanek
2009-08-20 16:48 ` Robert Millan
2009-08-20 16:20 ` Robert Millan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4A8C5CF7.9090408@duboucher.eu \
--to=thomas@duboucher.eu \
--cc=grub-devel@gnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.