top | item 47212285

(no title)

eqvinox | 5 hours ago

Not exactly surprising; unless you establish some type of shared secret between the TPM and CPU (e.g. by burning it into fuses in both devices, or through some signature scheme), the bus connecting the two will always be a problem…

discuss

order

Neywiny|3 hours ago

I've thought about it but haven't checked too hard: can they not do a key exchange? In my existing research I've found no reason they can't, just that they don't.

jcalvinowens|3 hours ago

They often do, but it can be MITM'd without some sort of authentication, which generally requires something to be installed in the factory.