Skip Links

Network World

Julie Bort

Microsoft guffaws at the severity of Black Hat Bitlocker/TPM hack

Microsoft insists risk is when used with optional Windows 7 "enhanced PIN" feature.

By Microsoft Subnet on Fri, 02/12/10 - 2:20pm.

Microsoft on Friday downplayed the risk of using Trusted Platform Module chips after Black Hat researchers demonstrated a hack of them last week. TPM, the bases of Windows hard drive encryption features like BitLocker, is not to be feared because the hack requires physical ownership of the box, special equipment and IC knowledge, says Paul Cooke on the Windows Security Blog.

He wrote:

"Since that presentation, I have had plenty of questions from customers wanting to know how this might affect Windows. The answer? We believe that using a TPM is still an effective means to help protect sensitive information and accordingly take advantage of a TPM (if available) with our BitLocker Drive Encryption feature in Windows 7.

The attack shown requires physical possession of the PC and requires someone with specialized equipment, intimate knowledge of semiconductor design, and advanced skills. While this attack is certainly interesting, these methods are difficult to duplicate, and as such, pose a very low risk in practice. Furthermore, it is possible to configure BitLocker in a way that mitigates this unlikely attack."

The Black Hat researcher who hacked TPM said of it, "The TPM 1.2 chip is not as secure as the vendor tries to tell you it is," Tarnovsky said. "I can recover all your secrets inside this chip. Your keys to the Xbox 360, the licensing chip," plus the RSA cryptoengine, if it's used. "There's nothing in this device I can't see." 

TPM, was developed as an industry specification for hardware-based computer security by the Trusted Computing Group, a consortium that originally included AMD, Intel, Hewlett-Packard, IBM, and Microsoft. It has been implemented in hardware by Infineon and other manufacturers, but Microsoft is best known for using it, not just in its BitLocker feature for Windows, but in other products including Xbox 360.

Cooke insists that when Microsoft designed BitLocker for Windows 7, it took into account TPM's vulnerabilities. The company should have known them as this isn't the first time TPM was hacked. In 2007, Black Hat researchers caused a stir when they promised to demonstrate how to compromise TPM. That live demonstration never occurred. It mysteriously vanished from the program with the researchers refusing to comment to the press about it. Then in late 2009 it was TPM-hack mania all over again, when German researchers released a paper documenting a hack. Microsoft downplayed the threat then, too.

Microsoft has added an optional feature to BitLocker to thwart a vulnerable TPM, says Cooke:

"The engineering team changed the cryptographic structure for BitLocker when configured to use enhanced pin technology, discussed in the BitLocker Drive Encryption in Windows 7: Frequently Asked Questions. As a result, an attacker must not only be able to retrieve the appropriate secret from the TPM, they must also find the user-configured PIN. If the PIN is sufficiently complex, this poses a hard, if not infeasible, problem to solve in order to obtain the required key to unlock the BitLocker protected disk volume."

BitLocker can be configured with a numerical personal identification number (PIN) of 4 to 20 characters. Or admins can flip on the enhanced PIN feature, that allows the use of any keyboard character to allow for more possible PIN combinations. This isn't activated by default, Microsoft says. To use it, "you must enable the Allow enhanced PINs for startup Group Policy setting before adding the PIN to the drive. By enabling this policy, all PINs created can utilize full keyboard characters."

BitLocker, which Microsoft debuted in higher-end versions of Windows Vista, is included only in Windows 7 Ultimate and Windows 7 Enterprise , available only to companies and organizations that buy Windows licenses in volume, as well as Windows Server 2008 and Server 2008 R2. The software encrypts disk volumes and locks them with a PIN, USB-based key device or, if the computer includes one, a Trusted Platform Module (TPM) chip.

Like this post? Check out these others.

Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
Follow All Microsoft Subnet bloggers on Twitter
Follow Julie Bort on Twitter

About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft