Hardware Hacking to Bypass Bios Passwords
blog.cybercx.co.nz
blog.cybercx.co.nz
My gripe is the eBay sellers and liquidators who want to sell a BIOS-locked laptop at full price. If a seller can't handle removing/resetting this password, then they shouldn't be selling it, or at the very least, list it as a $5 parts machine.
Put another way, a modern computer can be thought if as a network of relativity simple devices, of which the eeprom is one. Normally we assume that an attacker does not have access to this network. If the attacker does have access to this network, the game is lost. Everything about the network is unencrypted.
With full-disk encryption, taking the hard drive is not that useful. Firmware passwords are one link in securing the boot chain; secure boot is meaningless if attacker can just modify firmware or its config. So the password should offer protection against evil maid style attacks.
If a user enters the secret key on a compromised system then the game would be up. You would need to wait until the user decided to change the security processor to intercept quietly.
This eeprom, being security relevant, should be signed by the TPM, read into RAM, and if the signature check fails then the machine should consider itself stolen.
The only recovery method should be to replace the EEPROM contents with another valid image, also signed by the TPM. And that image should be available from the manufacturer for anyone able to show they are the device owner.
Simply?
Did you just equate resetting a bios password with wiring up a TPM and generating a new key pair?
BIOS settings are "measured" into the TPM, into a set of "platform configuration registers" (PCRs). The TPM itself takes no position on what the "correct" value of the PCRs is; however, it is possible to bind data against the PCRs. For instance, you can bind your disk encryption keys against the PCRs. Then, if the eeprom changes, the PCRs will be different, and the TPM will refuse to give you the disk encryption key.
The hardware itself is still valuable in the sense that a common thief cares about, but all of your data is protected, and you are not any more risk of using a compromised system then if the attacket simply swapped the unit for one that looks similar.
Anti theft protection needs to make the hardware unusable when triggered sadly... Apples iCloud lock effectively does this - locked iDevices sell on the black market for only about 20% of what an unlocked device sells for - and that 20% represents the values of the fraction of components that are not serial number locked.
10 year old, last lenove gen where this was possible
This is a legitimately hard problem to solve! Unless firmware starts using authenticated sessions with TPMs (in which the traffic over the easy to sniff bus is encrypted), swapping out the TPM is going to be a plausible vector for someone with physical access to the machine. Moving to fTPMs (in which the TPM stack runs as a software component on a segregated chip somewhere else on the device, such as the Intel Management Engine or the AMD Platform Security Processor) or an on-die TPM (such as Microsoft's Pluton) makes it massively more difficult to carry out this kind of attack.
tl;dr - unless you're introducing strong cryptography into things, trying to make security happen over unauthenticated buses is probably not going to work well for you
If you're that paranoid, then you can buy anti-tamper stickers. I'm not joking BTW, I think some of those are pretty damn impressive.
Great security there.
Note: If I own the laptop and don't have the password, I'm at the mercy of the vendor. And does the vendor want me to use my old hardware, or buy a new one?!