|
|
|
|
|
by bri3d
28 days ago
|
|
I'm glad we were able to move past "We don't know how that mechanism works, it could just be a totally separate gate that IS bypassable" and into the actual way the mechanism works! > The article shows that the PIN-entangled key material can still be downloaded directly from the TPM. Not exactly, the TPM has PolicyAuthValue(PIN), so the PIN also needs to be provided to the TPM to unseal the material, and the hardware anti-hammering should prevent brute forcing it this way. The blog post documents dumping the PIN-entangled key material by MITM-ing the TPM communication while a user enters the PIN; the entanglement is a belt-and-suspenders approach. |
|
Where are you seeing that? I can't find it in the article.
It wouldn't make sense to me for that to be the case if the article details how the driver does it own unwrapping/decryption after the KP is extracted. Plus it would probably mean they're lying about TPM+PIN being defeatable.
> The blog post documents dumping the PIN-entangled key material by MITM-ing the TPM communication while a user enters the PIN
I really don't think so... the screenshot with the PIN entry I think was only for hooking his debugger up in order to reverse the driver's decryption process. I don't see where they mention how/when the KP is actually extracted. It looks to me like it's transmitted during boot _before_ the PIN entry, so that the software driver can decrypt it after the user enters the PIN.
They list the steps as:
1. Extract TPM data. The TPM data is encrypted Key Protector (aka KP).
2. Generate the decryption key of KP
3. Decrypt KP
4. Extracting encrypted VMK
5. Decrypt VMK using KP
I didn't see anything about needing to enter a PIN in order to get the TPM data.
If the TPM required a PIN to extract anything, I think there would be no need to manually decrypt anything in software as they show with the python code.
Of course I could be wrong... please feel free to provide more info.