73 karma · joined August 24, 2023
This dongle is very likely to be this original attack https://github.com/JohannesObermaier/f103-analysis/tree/mast... but now packaged. If you want to read more this repo has the best doc: https://github.com/CTXz/stm32f1-picopwner. It's a multi-step attack where a payload is executed from persisted SRAM (RDP1 means you can read/write to it) after a quick reset. The fact that they mention freezing the chip heavily weighs in that direction since it's needed for higher clock chips.
Where it states: Module dTPM 2.0 (Discrete Trusted Platform Module)
Same for HP EliteBook and ProBooks: https://h20195.www2.hp.com/v2/GetPDF.aspx/c08049273.pdf
Edit: got in touch with an admin:
C-00000291-00000000-00000029.sys SHA256 1A30..4B60 is the bad file (timestamp 0409 UTC)
C-00000291-00000000-00000030.sys SHA256 E693..6FAE is the fix (timestamp >= 0527 UTC)
Do not rely on the hashes too much as these might vary from org to org I've read.
All RCEs are classified in either unauthenticated or authenticated, the former being the worst (or best if you're a researcher/hacker).
> Errr... no. Using no TPM of any kind decreases your security.
You're right, I wrote too fast, sorry about that. What I meant to say is that it discrete TPM with no PIN is an inferior solution compared to PIN/passphrase or fTPM. Also I should have added that it gives the illusion of security which I hinted at in the foreword. I'm leaving it as is for now, the discussions here are interesting.