|
|
Log in / Subscribe / Register

KRACK, ROCA, and device insecurity

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 4:36 UTC (Thu) by eternaleye (guest, #67051)
Parent article: KRACK, ROCA, and device insecurity

> The ROCA vulnerability affects keys that have been generated on keycards

Note that it's not just keycards - Infineon-made TPMs, such as are in many Linux laptops, are also affected.


to post comments

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 4:38 UTC (Thu) by eternaleye (guest, #67051) [Link] (3 responses)

...well, many laptops _period_ really. Incidentally, Windows BitLocker uses the TPM to seal the disk encryption key...

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 15:23 UTC (Thu) by nix (subscriber, #2304) [Link] (2 responses)

Chromebooks also use it for the platform key. Fixing the weak keys on Chromebooks requires losing all your personal data. God knows how (or even if) you can fix a BitLocker-encrypted drive encrypted with a weak key.

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 15:24 UTC (Thu) by nix (subscriber, #2304) [Link]

Obviously I meant all your *locally-stored* personal data. (On Chromebooks that's a fairly important distinction!)

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 15:34 UTC (Thu) by mjg59 (subscriber, #23239) [Link]

Depends on your threat model. If nobody's had a chance to extract key material from your system, simply re-encrypt the aes key with a good rsa key and shred the old key blob.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds