TPM–Fail: TPM Meets Timing and Lattice Attacks
tpm.fail
tpm.fail
Storage would be encrypted with a symmetric AES key, this only leaks asymmetric ECDSA signing keys
Because this would only leak private keys inside the device, you can only attack Trusted Boot (where producing trusted signatures is important), not Secure Boot (which only verifies signatures that were produced elsewhere).
It's used to store th private key of user certificates, but those are PIN protected presumably. But a key that isn't supposed to be extractible may well be so.
The reference implementation of TPM 2.0 leaves the choice of the crypto library up to the platform vendor. If my suspicions are correct, it sounds like some of the platform vendors decided to use crypto libraries vulnerable to timing attacks. Hmmm...
Microsoft, on the other hand, seems to support OpenSSL and wolfSSL in their simulator[2].
[1] - http://ibmswtpm.sourceforge.net/ibmswtpm2.html [2] - https://github.com/microsoft/ms-tpm-20-ref
tpm2-tools are CLI utilities that use the tpm2-tss library.