logoalt Hacker News

engcoachyesterday at 4:42 PM2 repliesview on HN

Please note: A well-funded organization, like a government, can derive the keys from the TPM hardware using an electron microscope.


Replies

Retr0idyesterday at 6:02 PM

Also note that there are plenty of viable attack methods that don't even require key extraction, such as asking the TPM to sign arbitrary data.

deltoidmaximusyesterday at 6:35 PM

That's assuming they don't just have a backdoor inserted expressly for this purpose. Now only the rich or powerful can produce an "authentic" recording of an event and the same system can be used to hunt down whistleblowers and political enemies by looking up who bought the camera.