Security chip that does encryption in PCs hacked
February 8, 2010 By JORDAN ROBERTSON , AP Technology Writer
In this Tuesday, Feb. 2, 2010 photo, Chris Tarnovsky poses for photos after speaking at the Black Hat Briefings in Arlington, Va. Tarnovsky figured out a way to break chips that carry a "Trusted Platform Module," or TPM, designation. Such chips are billed as the industry's most secure and are estimated to be in as many as 100 million personal computers and servers, according to market research firm IDC. (AP Photo/Jacquelyn Martin)
(AP) -- Deep inside millions of computers is a digital Fort Knox, a special chip with the locks to highly guarded secrets, including classified government reports and confidential business plans. Now a former U.S. Army computer-security specialist has devised a way to break those locks.
The attack can force heavily secured computers to spill documents that likely were presumed to be safe. This discovery shows one way that spies and other richly financed attackers can acquire military and trade secrets, and comes as worries about state-sponsored computer espionage intensify, underscored by recent hacking attacks on Google Inc.
The new attack discovered by Christopher Tarnovsky is difficult to pull off, partly because it requires physical access to a computer. But laptops and smart phones get lost and stolen all the time. And the data that the most dangerous computer criminals would seek likely would be worth the expense of an elaborate espionage operation.
Jeff Moss, founder of the Black Hat security conference and a member of the U.S. Department of Homeland Security's advisory council, called Tarnovsky's finding "amazing."
"It's sort of doing the impossible," Moss said. "This is a lock on Pandora's box. And now that he's pried open the lock, it's like, ooh, where does it lead you?"
Tarnovsky figured out a way to break chips that carry a "Trusted Platform Module," or TPM, designation by essentially spying on them like a phone conversation. Such chips are billed as the industry's most secure and are estimated to be in as many as 100 million personal computers and servers, according to market research firm IDC.
When activated, the chips provide an additional layer of security by encrypting, or scrambling, data to prevent outsiders from viewing information on the machines. An extra password or identification such as a fingerprint is needed when the machine is turned on.
Many computers sold to businesses and consumers have such chips, though users might not turn them on. Users are typically given the choice to turn on a TPM chip when they first use a computer with it. If they ignore the offer, it's easy to forget the feature exists. However, computers needing the most security typically have TPM chips activated.
"You've trusted this chip to hold your secrets, but your secrets aren't that safe," said Tarnovsky, 38, who runs the Flylogic security consultancy in Vista, Calif., and demonstrated his hack last week at the Black Hat security conference in Arlington, Va.
The chip Tarnovsky hacked is a flagship model from Infineon Technologies AG, the top maker of TPM chips. And Tarnovsky says the technique would work on the entire family of Infineon chips based on the same design. That includes non-TPM chips used in satellite TV equipment, Microsoft Corp.'s Xbox 360 game console and smart phones.
That means his attack could be used to pirate satellite TV signals or make Xbox peripherals, such as handheld controllers, without paying Microsoft a licensing fee, Tarnovsky said. Microsoft confirmed its Xbox 360 uses Infineon chips, but would only say that "unauthorized accessories that circumvent security protocols are not certified to meet our safety and compliance standards."
The technique can also be used to tap text messages and e-mail belonging to the user of a lost or stolen phone. Tarnovsky said he can't be sure, however, whether his attack would work on TPM chips made by companies other than Infineon.
Infineon said it knew this type of attack was possible when it was testing its chips. But the company said independent tests determined that the hack would require such a high skill level that there was a limited chance of it affecting many users.
"The risk is manageable, and you are just attacking one computer," said Joerg Borchert, vice president of Infineon's chip card and security division. "Yes, this can be very valuable. It depends on the information that is stored. But that's not our task to manage. This gives a certain strength, and it's better than an unprotected computer without encryption."
The Trusted Computing Group, which sets standards on TPM chips, called the attack "exceedingly difficult to replicate in a real-world environment." It added that the group has "never claimed that a physical attack - given enough time, specialized equipment, know-how and money - was impossible. No form of security can ever be held to that standard."
It stood by TPM chips as the most cost-effective way to secure a PC.
It's possible for computer users to scramble data in other ways, beyond what the TPM chip does. Tarnovsky's attack would do nothing to unlock those methods. But many computer owners don't bother, figuring the TPM security already protects them.
Tarnovsky needed six months to figure out his attack, which requires skill in modifying the tiny parts of the chip without destroying it.
Using off-the-shelf chemicals, Tarnovsky soaked chips in acid to dissolve their hard outer shells. Then he applied rust remover to help take off layers of mesh wiring, to expose the chips' cores. From there, he had to find the right communication channels to tap into using a very small needle.
The needle allowed him to set up a wiretap and eavesdrop on all the programming instructions as they are sent back and forth between the chip and the computer's memory. Those instructions hold the secrets to the computer's encryption, and he didn't find them encrypted because he was physically inside the chip.
Even once he had done all that, he said he still had to crack the "huge problem" of figuring out how to avoid traps programmed into the chip's software as an extra layer of defense.
"This chip is mean, man - it's like a ticking time bomb if you don't do something right," Tarnovsky said.
Joe Grand, a hardware hacker and president of product- and security-research firm Grand Idea Studio Inc., saw Tarnovsky's presentation and said it represented a huge advancement that chip companies should take seriously, because it shows that presumptions about security ought to be reconsidered.
"His work is the next generation of hardware hacking," Grand said.
©2010 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
-
Infineon Announces Trusted Platform Module to Enhance PC Security
May 31, 2005 |
not rated yet |
0
-
New Security Chip Card Controllers Make Electronic Identity Cards and Passports Even More Secure
Jul 16, 2004 |
not rated yet |
0
-
PC Chip Will Protect Users From Hackers and Viruses
Sep 16, 2004 |
not rated yet |
0
-
Trust Linux!
Nov 20, 2009 |
not rated yet |
0
-
Infineon says 65nm phone chip is available
May 12, 2006 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (29) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
-
Need help with my technical fest!
Jan 19, 2012
- More from Physics Forums - Computing & Technology
More news stories
Samsung can continue selling Galaxy tabs in Germany: court
South Korea's Samsung Electronics can continue to sell its Galaxy Tab 10.1N tablet computer in Germany, a German court ruled Thursday, rejecting a bid by arch-rival Apple to have them banned.
1 hour ago |
not rated yet |
1
Soraa LED light may dim 50-watt halogen rivals
(PhysOrg.com) -- Soraa, a Fremont, California company founded in 2008, this week launched its first product, a light that uses LEDS (light emitting diodes). The "Soraa LED MR16 lamp" is the "perfect" replacement for traditional ...
Researchers discover potential key to lowering energy costs of cell phones and data centers
(PhysOrg.com) -- A systematic analysis of power usage in microprocessors could help lower the energy consumption of both small cellphones and giant data centers, report computer science professors from The University of Texas ...
Technology / Computer Sciences
2 hours ago |
not rated yet |
0
|
China's Alibaba raising $3bn for Yahoo! stake: report
Chinese online commerce giant Alibaba plans to borrow $3 billion to buy back the stake Yahoo! owns in the company, a report said Thursday, as the struggling US Internet firm overhauls its Asia holdings.
3 hours ago |
not rated yet |
0
Lenovo 3Q profit up by half, warns of disk supply
(AP) -- Lenovo Group Ltd., the world's second biggest personal computer maker, said Thursday that quarterly profit grew by more than half but warned hard drive costs would remain high amid a global shortage.
3 hours ago |
not rated yet |
0
New Zealand team finds early plant arrivers dominated landscape
(PhysOrg.com) -- It seems intuitive that not all plant species could have taken a foothold on land at the same time all those millions of years ago as conditions on Earth evolved to the point where they could survive; some ...
New views show old NASA Mars landers
(PhysOrg.com) -- The High Resolution Imaging Science Experiment (HiRISE) camera on NASA's Mars Reconnaissance Orbiter recorded a scene on Jan. 29, 2012, that includes the first color image from orbit showing ...
Engineers find inspiration for new materials in Piranha-proof armor
(PhysOrg.com) -- Its a matchup worthy of a late-night cable movie: put a school of starving piranha and a 300-pound fish together, and who comes out the winner?
Black holes and star formation
(PhysOrg.com) -- It has long been recognized that galaxy mergers or even close interactions can play a vital role in shaping the morphology of galaxies. One way they can do so, it is thought, is by triggering ...
Deciding to go left or right: Researchers use device to determine that lower animals can navigate too
For decades, scientists have associated binary decision making opting to go left or right with higher-ranking animals, including humans. A team of Harvard researchers, however, is rewriting that ...
New target for Alzheimer's drugs
(Medical Xpress) -- Biomedical scientists at the University of California, Riverside have identified a new link between a protein called beta-arrestin and short-term memory that could open new doors for the ...
Feb 08, 2010
Rank: 4.8 / 5 (4)
Feb 08, 2010
Rank: 1.2 / 5 (5)
Although once he broke the code, it probably wouldn't be too hard for someone that smart to make a device from a cell phone or ipod to do the "reading" for him...which must be what he used the cell phone for...
...but yeah, he pretty much has the entire instruction set for machine code memorized...for probably all chipsets...which is incredible...
i.e. reverse engineer machine code "blind" while it is running...
I.Q. = incalculable?!?!
Feb 08, 2010
Rank: 2.3 / 5 (3)
I wouldn't be very good at it, but they dont' have to know that...
"sure, that new security chip is working just fine, still haven't managed to hack it yet..."
Feb 08, 2010
Rank: 5 / 5 (6)
A: Organized crime.
Feb 08, 2010
Rank: 5 / 5 (2)
Feb 08, 2010
Rank: not rated yet
True. We know Microsoft puts spyware built into their OS, but I doubt anyone would even know if a hardware developer had spy-ware built into the firmware. I mean, they could steal all your personal info and all of your business info, AND spy on your browsing habits, all with a built-in program on the processor and other chips, and none of us would even know it was happening...
...hm...maybe they already are doing that, and that explains the BLOAT of windows and other software...
----
"Just because you're paranoid doesn't mean everyone isn't watching."
Feb 08, 2010
Rank: 5 / 5 (1)
In corporate/government places individuals almost always send unencrypted data to printers, splice the wire near a printer -> save to flash until satisfied -> go home and read data.
Just the beginning of those exploitable angles. >:]
Feb 08, 2010
Rank: 5 / 5 (1)
Hey look, Infineon's new corporate slogan!
Feb 09, 2010
Rank: not rated yet
Feb 09, 2010
Rank: not rated yet
Feb 09, 2010
Rank: 1 / 5 (2)
So they thought it would only be hacked by stupid, undetermined people?
Feb 09, 2010
Rank: 5 / 5 (1)
The TPM does not provide any sort of security unless you're using TPM enabled cryptography suites. For 99% of people this is irrelevant on their home machines. Where this has an impact is in the fields of finance, medical records, and other personal information brokers.
Feb 14, 2010
Rank: not rated yet