TPM with no PIN is practically bitlocker with no password. A high entropy PIN happens to solve this entire attack.
TPM with no PIN is practically bitlocker with no password. A high entropy PIN happens to solve this entire attack.
The PCRs attest system state to the OS, yes. Though the verified boot (PSB/Secure Guard + Secure Boot) chain is supposed to provide the same security there. Provided we assume security features aren't broken by design...
The memory encryption features are a solution to very specific problems.
If the CPU is able to access the memory, then any exploit that gains the execution context of the legitimate user can also access the memory. If it doesn't, the normal memory access control should be enough.
I'm iffy on how well they protect against the various side channels. Mostly because I haven't looked far enough into it.
IME it protects against cold boot attacks, a theoretic attack of a logic analyzer on the memory bus, and potentially to some degree unbounded reads. But the latter only with very limited gadgets.
There's also this project https://www.cs1.tf.fau.de/research/system-security-group/tre... which reserves some CPU registers (iirc. A hardware aes accelerator on one core) to prevent key leakage.