Gentoo Archives: gentoo-user

From: Rich Freeman <rich0@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] New Intel vulnerability?
Date: Fri, 06 Mar 2020 19:39:44
Message-Id: CAGfcS_kCyRk=p=Fo7VLPo6WxC_r603AHPYmkipMNM3sEvb5-Pw@mail.gmail.com
In Reply to: Re: [gentoo-user] New Intel vulnerability? by Wols Lists
1 On Fri, Mar 6, 2020 at 2:07 PM Wols Lists <antlists@××××××××××××.uk> wrote:
2 >
3 > On 06/03/20 13:48, Rich Freeman wrote:
4 > > If you fall into this camp you need to still update your firmware to
5 > > address the non-TPM-user and to avoid making it trivial for software
6 > > to steal your keys/etc. However, you need to be aware that you are no
7 > > longer secure against physical theft of your device. Somebody who
8 > > steals your laptop with passwordless encryption might be able to break
9 > > the encryption on your device.
10 >
11 > It's worse that that, he's dead, Jim!
12 >
13 > The summary on LWN is an easy read. Somebody who steals your Intel
14 > laptop WILL be able to break the encryption on your device.
15 >
16 > tl;dr summary - the microcode that *boots* the cpu has been compromised.
17 > So even while it is setting up tpm and all that malarkey, malware can be
18 > stealing keys etc.
19
20 They don't detail the effort required. If the firmware is patched it
21 sounds like it still requires tinkering with hardware. However, there
22 really isn't nothing you said that doesn't agree with what I said.
23
24 Whether they "WILL" be able to break the encryption on your device
25 depends a lot on the details and the knowledge of the attacker. Hence
26 the reason I said "might." In any case, might is good enough to not
27 rely on a broken security feature.
28
29 > Which means that Intel's master signing key will soon be cracked and
30 > compromised.
31
32 Yes, but keep in mind the signing keys have nothing to do with disk
33 encryption. It is for remote attestation. Hence my Netflix comment.
34
35 --
36 Rich

Replies

Subject Author
Re: [gentoo-user] New Intel vulnerability? aisha <aisha@×××××.cc>
Re: [gentoo-user] New Intel vulnerability? Wols Lists <antlists@××××××××××××.uk>