Hacker News new | ask | show | jobs
by shawnz 866 days ago
These kinds of attacks aside, the intent is that you need to turn on the PC and then actually boot to the intended operating system, which is then protected with a login screen
2 comments

Yeah fair enough. The login screen should still provide good protection in a TPM-only scenario. (Although it had some vulnerabilities in the past: https://secret.club/2021/01/15/bitlocker-bypass.html)
Except that if you can sniff the encryption keys, you can tamper with the OS and for example remove the password...
That's why I caveated my explanation with "these kinds of attacks aside": this video describes such a bus sniffing attack
I've read your message too quickly ;)