[51084] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: TPM & disk crypto

daemon@ATHENA.MIT.EDU (Alexander Klimov)
Mon Oct 9 08:13:22 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 9 Oct 2006 11:54:51 +0200 (IST)
From: Alexander Klimov <alserkli@inbox.ru>
To: cryptography@metzdowd.com
In-Reply-To: <1160170648.4937.48.camel@localhost.localdomain>

On Fri, 6 Oct 2006, Erik Tews wrote:
> > And the TPM knows that your BIOS has not lied about the checksum of grub
> > how?
>
> The TPM does not know that the BIOS did not lie about the checksum of
> grub or any other bios component.
>
> What you do is, you trust your TPM and your BIOS that they never lie to
> you, because they are certified by the manufature of the system and the
> tpm. (This is why it is called trusted computing)

IIUC, TPM is pointless for disk crypto: if your laptop is stolen the
attacker can reflash BIOS and bypass TPM. Moreover, TPM is actually
bad for disk crypto: without it you lose your data only if your HDD
dies, now you lose your data if your HDD dies *or* if you motherboard
dies. If the user is not experienced in BIOS reflashing, they also
lose their data if OS crashes and refuses to boot (not uncommon for
some common OSes).

-- 
Regards,
ASK

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post