Anyway, if you rely on BitLocker in TPM mode (boot without PIN), you should know that anyone can steal your computer, sniff 32 bytes off of the LPC bus, stick them into libbde, and decrypt your disk. Yes, it's that easy. Solder 7 wires to $favorite_fpga_board, decrypt drive.
If you can compromise TrustZone then you can easily compromise both DE and CE. A 6-digit PIN provides ~zero cryptographic security, it all relies on the Keymaster implementation for both CE and DE.
-
-
I'm not saying it's easy, but I'm not betting the security of my data on someone having implemented a complet TrustZone stack securely, given what attempts I've seen so far. And that's not counting hardware attacks.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.