Crypto Ticker:
sysadmin from Cyber Security News

HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys

Abinaya
Monday at 16:26
9 Views
0 Comments
HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys

A security researcher has disclosed a boot-chain weakness in HP ThinPro 8 and 9 that could allow attackers with physical access to a thin client to extract its LUKS disk-encryption key. The issue affects HP thin clients in which LUKS2 protects the operating system’s encrypted root partition, and the decryption key is sealed inside the device’s Trusted Platform Module (TPM). While this design is intended to prevent data theft from removed storage drives, the researcher found that the TPM policy does not fully validate the software loaded during Boot. HP ThinPro uses a custom utility, called hptc-tpm-tool, to retrieve the LUKS key from the TPM during startup. An initramfs script named unseal_key requests the key and passes it...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!