[binary] TPMs and Baseband Bugs

Day[0] - A podcast by dayzerosec

Categories:

This week we go a bit deeper than normal and look at some low level TPM attacks to steal keys. We've got a cool attack that lets us leak a per-chip secret out of the TPM one byte at a time, and a post about reading Bitlocker's secret off the SPI bus. Then we talk about several Shannon baseband bugs disclosed by Google's Project Zero. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/210.html [00:00:00] Introduction [00:01:14] Spot the Vuln - Sanitize Now or Later [00:03:50] faulTPM: Exposing AMD fTPMs’ Deepest Secret [00:18:33] Stealing the Bitlocker key from a TPM [00:24:01] Shannon Baseband: Integer overflow when reassembling IPv4 fragments The DAY[0] Podcast episodes are streamed live on Twitch twice a week: -- Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities -- Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits. We are also available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec You can also join our discord: https://discord.gg/daTxTK9