Betrayal of Reputation: Trusting the Untrustable Hardware and Software with Reputation

No ratings

Presented at BlueHatShanghai 2019 by

Reputation is based on trust, and people normally trust the products produced by global companies like Intel, HP, Dell, Lenovo, GIGABYTE, and ASUS because of their reputation. Their products are built with some kinds of hardware and software that are made by them or confirmed by them. Global companies have spent their efforts making and managing high-quality products for profit and reputation. So, trust based on reputation works properly. Despite their efforts, the complexity of hardware and software has been increasing. Because of it, it is hard to check the correctness and completeness of specifications and implementations related to their products. In this talk, I introduce the case that hardware and software, especially BIOS/UEFI firmware, Intel Trusted Execution Technology (TXT), and Trusted Platform Module (TPM), betray your trust. Reputable companies defined specifications and implemented them, and the TPM with the UEFI/BIOS firmware and Intel TXT has been widely used and responsible for the root of trust. I found two vulnerabilities, CVE-2017-16837 and CVE-2018-6622, related to the sleep process. Unlike previous researches, the vulnerabilities can subvert the TPM without physical access. To mitigate the vulnerabilities, I also introduce countermeasures and a tool, Napper, to check the vulnerabilities. Sleep process is a vital part of the vulnerabilities, so Napper makes your system take a nap and check them.