Break into this CEO’s laptop to steal company secrets and plant malware
twitter.com
twitter.com
If there's a TPM password, this attack becomes infeasible because the TPM won't release the keys without the password. And you generally can't brute force the TPM without triggering the hardware lockout.
The company's IT department can require TPM+Password in Group Policy so that every system in the organization uses TPM+Password, but I guess you could have a stubborn CEO who demands a less secure policy.
As of Windows 8, it was possible to replace ciphertext on a BitLocker-encrypted drive to compromise known Windows binaries.[0] This would allow the attacker to take control of the system on next boot, though I don't know if those attacks are still practical.
[0] https://cryptoservices.github.io/fde/2014/12/08/code-executi...
How many here would recognize that Evil Maid has swapped out your work machine with an identical model? It would be rigged to boot into an identical login screen and send your password back to the guy with the real laptop. That's what happens when everyone has the same shiny new machines (Apple). Give me a machine with a few scratches and custom boot screen.
At that point, it's a race between how quickly the attackers can exploit temporary access to the CEO's network resources and how quickly the CEO and their IT folks figure out that they need to cut off the stolen laptop's network access and user credentials.
You don't need login to succeed, just fail convincingly.
That moment when when the CEO is back in the hotel room, and realizes he just authenticated to a laptop that was not his would be an ideal moment for the assassin that looks very similar to him to exit the hotel bathroom, pop the CEO, dress in his clothes, and proceed to the bank for wire transfer shenanigans.
More common than one would think. Also, more common than one would hope: CEOs who insist on their favorite MacBookPro which they share with family. :-)
That is how like half the world are doing it.
The level of pain to reset the TPM password when 1% of your company forgets their password after each holiday / weekend drinking / password change on Friday / because they're late for a meeting is just too high.
On the Chinese internets, there are kits exactly for exfiltrating both the PIN, and the key out of TPM chips.
Somebody solders them in, then a few month down the line, the intercepted key is either exfiltrated with the device, or remotely over bluetooth.
I think this is an interesting attack vector, but seems overly complicated especially if you can install a key logger(and probably do it faster).
https://www.computerweekly.com/blog/CW-Developer-Network/F-S...
Normal full disk encryption needs you to enter two passwords - one to decrypt the disk, another a minute or two later to log into the operating system. Your corporate IT helpdesk can remotely reset the latter password if you forget it, but the former can't be remotely reset. And if several people need to be able to boot a shared computer, they need to share the disk encryption password (which isn't winning any security awards).
Between the TPM and Secure Boot, the intention is that you sacrifice a certain amount of security - but in exchange, you can have only a single password prompt, a password IT can remotely reset, and no shared boot password.
At least with LUKS you can have multiple passwords for unlocking a disk so you can have one master password and user password(s) for the same machine.
Having to enter two passwords doesn't seem like a big issue for high security HW like a CEO's laptop. In fact that's standard procedure at my company.
Luks implements this by encrypting the actual key multiple times, once with each password. So if one person turns evil before you remove their password or a password is leaked, you can still consider the disk compromised.
In an Active Directory environment, Group Policy can store BitLocker recovery keys within AD. Self-service key recovery and rotation is an option with Intune and other device management platforms.
In the context of a personal computer, signing in with or linking a Microsoft account can provide the same functionality.
> shared computer
BitLocker Network Unlock solves this for fixed-location devices.
GSuite had (maybe still has) a tool for ranking password strength across your org. Used it once & sorted from weakest to strongest. My results were practically the org chart from top to bottom.
If anything the example is arbitrarily harder rather than easier.
In that course I have seen a bunch of blog posts where people found bugdoors or easy auth bypasses in these drive controller encryption schemes. Is that still a thing?
<https://support.microsoft.com/en-us/topic/september-24-2019-...>
Twitter sucks ass and I don't want to scroll for a week to read your blog post. Please, please, just copy+paste it into a blog post and link to it on your Twitter. I swear I will "like & subscribe" to your Blog if you're worried about not getting enough eyeballs. I just do not want to ever have to look at Twitter.
Tweets get lost, they're usually meaningless, they aren't editable, you have to scroll through them, the comments aren't nested well, the URI is garbage, you can't group them by tags, etc.
A blog could be designed to encourage abbreviated blog posts, and even help you split a post up for re-tweeting if you really wanted. Even auto-resize just to make it easier to see the entire thing in one page. Yet would retain all the great properties of legit blogs. You could call it "tldrblog".