logoalt Hacker News

tapoxitoday at 1:28 AM1 replyview on HN

This is called the Endorsement Key, and you're correct, it never leaves the TPM. The TPM is a "black box" to the OS.


Replies

digiowntoday at 4:24 AM

Ah, got it. With enough motivation this is still pretty easily defeated though. The key is in some kind of NVRAM, which can be read with specialized equipment, and once it's out, you can use it to spoof signatures on a different machine and cheat as usual. The TPM implementations of a lot of consumer hardware is also rather questionable.

These attestation methods would probably work well enough if you pin a specific key like for a hardened anti-evil-maid setup in a colo, but I doubt it'd work if it trusts a large number of vendor keys by default.

show 1 reply