DefederateLemmyMl

  • Gen𝕏
  • Engineer ⚙
  • Techie 💻
  • Self hoster 🖧
  • Linux user 🐧
  • Ukraine supporter 🇺🇦
  • Pro science 💉
  • Dutch speaker
  • 0 Posts
  • 124 Comments
Joined 3 years ago
cake
Cake day: August 8th, 2023

help-circle


  • Second thing is, No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I’m just not publishing the PoC, I think what’s out there is already bad enough.

    The PoC for that goes to another school, in Canada.

    Edit:

    Downvoters don’t understand the nature of this exploit.

    Without PIN, the windows recovery software has full access to the encryption keys in the pre-boot environment. So to crack bitlocker in this case, a hacker only needs to find a bug in the WRE to get at the keys. => That’s the Yellowkey exploit.

    With a PIN, no Windows or Microsoft program has access to the bitlocker encryption keys until the PIN is provided, and it can’t be brute forced because the TPM protects against that. To exploit that, would require a attack on the TPM hardware itself, which would be absolutely massive if he could pull this off through software only and of a completely different nature than the Yellowkey exploit. It also wouldn’t have anything to do with Microsoft software, because it wouldn’t be in the loop for this.

    To use an analogy: Yellowkey is like beating a bank employee (the WRE) who knows the combination to the safe with a wrench until he gives you the combination. In an attack with a PIN, the bank employee doesn’t know the combination himself, so you can beat him with a wrench as much as you like, he’s not going to give you anything useful.

    Extraordinary claims require extraordinary evidence, and he has provided none. Furthermore, he has a bone to pick with Microsoft over a denied bug bounty, so he clearly has a motif to undermine trust in Microsoft products like bitlocker. All this, and knowing the typical hacker personality, leads me to believe that this is pure bluff. If he had something, he would show it.









  • The laws can absolutely be written such that companies are required to suspend service to any suspected child without requiring ID to use the service.

    The laws shouldn’t focus on “harming children” so much, but on “harming humans”.

    The big tech companies should be held responsible for the actual damage they are inflicting upon society, and their methods to artificially inflate “engagement” (or whatever the hell they call it) should be held to scrutiny. Whether or not the damage is inflicted upon an underage person or an adult, is merely a distraction.

    Those assholes would love it if we all had to identify ourselves and prove our age, if it means they get to keep inflicting their shit upon us.






  • Why would I throw it away, when I can give it to someone who needs it more, or sell it?

    Because selling is always a hassle, dealing with choosing beggars and scammers, and it may not be worth much anymore for general use.

    For example, my old PC is a i7 4770k… it can’t run Windows 11 or play remotely recent games. I don’t know anyone who could use this thing, so to save a few watts I took out the GPU, put it in eco mode and have been using it as my Linux server.

    My NUC uses 6-7W idle.

    I have played around with some mini PC’s (minisforum and beelink brand), they’re neat but they turned out to be not very reliable, two have already died prematurely, and unfortunately they are not end-user serviceable. Lack of storage expansion options is an issue as well, if you don’t just want to stack a bunch of external USB drives on top of each other.