First in-the-wild UEFI bootkit bypassing UEFI Secure Boot
welivesecurity.com
welivesecurity.com
This pivot means that the keys measured into PCR 7 of the TPM will change, which breaks the Bitlocker policy, which is presumably why stage 1 disables Bitlocker before exploiting the bootloader. This means it's also detectable using Remote Attestation (I think Microsoft's Device Health Attestation ought to notice, but haven't verified it), which is nice for all 3 of the people who've rolled that out.
In terms of why the known vulnerable bootloaders weren't already revoked - I have no inside knowledge here, but my guess would be the impact on users with existing install media (including factory restore images). We've revoked a bunch of vulnerable Linux bootloaders, but the level of pain involved in revoking a Windows one is almost certainly way higher.
Revoking other OSes install media en-masse is fine, but not Windows ?
I personally will always use a passphrase for device encryption.
Can you elaborate as to what is foolish about using a TPM?
https://wiki.archlinux.org/title/Lenovo_ThinkPad_X1_Carbon_(...
It's referring to dual booting windows but the same principles apply.
You want those modules signed by someone like Canonical, so you don't have to mess around with a MOK? If you use Ubuntu Core they'll be happy to - for about $100,000 per year per module.
Automatically unlocking hard drive encryption is less secure than just typing in a password at boot.
No OS-independent way of confirming the user's presence means it's less secure than a Yubikey.
No iphone-style activation lock, so it's useless as a theft deterrent.
No xbox-style main memory or system bus encryption, so no protection against evil maid attacks.
Too slow for servers to offload SSL or disk encryption to - so all the important keys end up being held in memory anyway.
The spec and interface are complicated as hell, so you know there's no chance this stuff is bug-free. You want a command line tool? We've got 99 command line tools. Literally.
The foundation of its security is the code of your system's BIOS, which we all know is some of the shittiest code out there.
So the TPM offers a hair-trigger system that'll destroy all your data if your BIOS vendor messes up and miscalculates a PCR value. The security benefits you get in return are pretty minor.
You can have arbitrarily complex TPM authorization policies for unlocking storage keys. You can have it be that the loaded firmwares and OS are trusted and (or or) you have to enter in a passphrase that only the TPM can verify, and/or you can have a recovery mechanism so that if some firmware got updated you could use a smartcard or whatever to authorize moving on anyways. So, while OSes that support TPMs for storage key recovery generally have -as you say- hair-trigger policies, that's not TPM's fault but the OS's, for they could develop much more interesting policies.
1. You'll have your master password, for which it asks when you first create it. You can make this absurdly long and consider it'll be used as a last resort (say you've lost everything else and your computer is broken - you only have the drive left).
2. You can then add Windows-style auto-unlock with the TPM. It works with systemd. You can of course choose whichever registers you like, the correct TPM device if you have several.
systemd-cryptenroll /dev/sda1 --tpm2-device=auto --tpm2-pcrs=0+1+7
3. If you're somewhat paranoid, you can have it ask for a PIN. Just add --tpm2-with-pin=true to the above.4. What if this is an external drive and / or often change your UEFI settings yet still need a quick unlock? Luckily, you have a FIDO2 device, so systemd's got you covered:
--unlock-fido2-device=auto instead of the tpm2
5. You can probably combine TPM + FIDO2, I've never tried it.Check the Arch wiki for more:
https://wiki.archlinux.org/title/Trusted_Platform_Module#Usi...
---
edit: it should be noted that even on Windows, there's a recovery key which allows you to unlock bitlocker if the TPM was cleared. It's not clear what the poster above said that the data would be nuked (unless, of course, you only count on the TPM and don't save that key somewhere).
Another backdoored closed piece of hardware ?
I recognize that I am decreasing my security a bit, but that tradeoff is worth it to me.
Fully agree, when I first read the HN story headline my initial reaction was where can I get a copy for use on my own machines.
</grump>
The cheapest Black Lotus cards are around $10k[1], an artist proof, signed Black Lotus may be worth around $800,000[2].
[1] https://www.tcgplayer.com/search/magic/product?productLineNa...
[2] https://www.rollingstone.com/product-recommendations/lifesty...
It's really no contest.
I can guess why they might do that, but also wonder if it's an actual international group (nice to see countries working together so well! /sarcasm), or they threw in a few extra plausible ones to mask their origin. For example, if they just picked Moldova, that's relatively small country and would narrow down their location to one city exactly.
Yes. Can you read and understand Russian?
There are others that are public: antichat, wwh-club, bhf. I'm not on it but I think the most "elite" forum is called Mazafaka and requires a substantial deposit and a recommendation from existing members.
Exploit.in is more technical than most of these forums but a lot of these people are not really very technically skilled they just have a very good understanding of how anti fraud systems work and how to circumvent them.
Bootkit samples https://github.com/hardenedvault/bootkit-samples
The short-term solution for workaround is to protect the OS runtime. Otherwise you'd have to build the defense-in-depth at very infrastructure level from scratch with hardware, firmware and OS with attestation service not only based on the "confidential computing" but typically TCG's trusted computing.
It's kinda a surprise that it's only detected in the wild now if it's that obvious.