Gentoo Archives: gentoo-user

From: aisha <aisha@×××××.cc>
To: gentoo-user@l.g.o
Cc: Rich Freeman <rich0@g.o>
Subject: Re: [gentoo-user] New Intel vulnerability?
Date: Fri, 06 Mar 2020 20:12:52
Message-Id: d48ad1e6782c07dca9351c94bb7673db@aisha.cc
In Reply to: Re: [gentoo-user] New Intel vulnerability? by Rich Freeman
1 I just fell in love with Intel a bit more.
2
3 ---
4 Aisha
5 blog.aisha.cc
6
7 On 2020-03-06 14:39, Rich Freeman wrote:
8 > On Fri, Mar 6, 2020 at 2:07 PM Wols Lists <antlists@××××××××××××.uk>
9 > wrote:
10 >>
11 >> On 06/03/20 13:48, Rich Freeman wrote:
12 >> > If you fall into this camp you need to still update your firmware to
13 >> > address the non-TPM-user and to avoid making it trivial for software
14 >> > to steal your keys/etc. However, you need to be aware that you are no
15 >> > longer secure against physical theft of your device. Somebody who
16 >> > steals your laptop with passwordless encryption might be able to break
17 >> > the encryption on your device.
18 >>
19 >> It's worse that that, he's dead, Jim!
20 >>
21 >> The summary on LWN is an easy read. Somebody who steals your Intel
22 >> laptop WILL be able to break the encryption on your device.
23 >>
24 >> tl;dr summary - the microcode that *boots* the cpu has been
25 >> compromised.
26 >> So even while it is setting up tpm and all that malarkey, malware can
27 >> be
28 >> stealing keys etc.
29 >
30 > They don't detail the effort required. If the firmware is patched it
31 > sounds like it still requires tinkering with hardware. However, there
32 > really isn't nothing you said that doesn't agree with what I said.
33 >
34 > Whether they "WILL" be able to break the encryption on your device
35 > depends a lot on the details and the knowledge of the attacker. Hence
36 > the reason I said "might." In any case, might is good enough to not
37 > rely on a broken security feature.
38 >
39 >> Which means that Intel's master signing key will soon be cracked and
40 >> compromised.
41 >
42 > Yes, but keep in mind the signing keys have nothing to do with disk
43 > encryption. It is for remote attestation. Hence my Netflix comment.