Integrity of hardware-based computer security is challenged - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Crackin' the Kraken bot. Listen now!

Network World's Newsmaker of the Week

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED WHITEPAPERS

Enterprise Linux: How Oracle Support Differentiates Itself in a Commodity Market Oracle

Linux has proven itself to be a versatile solution across a variety of hardware architectures to support workloads ranging from basic infrastructure services to enterprise-class database deployments. Today, Linux is commonly found operating in some capacity within most larger organizations, and over time, it has captured many of the same workloads that previously were deployed aboard RISC platforms running Unix operating systems. Read IDC's report on how Oracle support differentiates itself in a commodity market.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Learn how to Create a More Efficient Virtualized Data Center Novell

Find out how you can consolidate Windows workloads and create a more efficient virtualized data center in this informative webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization." Six concise webcast modules are available for your viewing. Watch them all consecutively or only the topics that interest you. The modules cover performance, user case studies, enterprise-level support, managing windows workloads, setup and configuration and the future of virtualization. Learn more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

Out of 19 vendors only 2 participated... This article would have been much more relevant if more vendors...- Anonymous

Join the Discussion

Integrity of hardware-based computer security is challenged

Withdrawn Black Hat paper hints at flaws in TPM security architecture
By Tim Greene , Network World , 06/27/2007
  • Social Web 
  • Email 
  • Feedback 
  • Close

A presentation scheduled for Black Hat USA 2007 that promised to undermine chip-based desktop and laptop security has been suddenly withdrawn without explanation.

The briefing, “TPMkit: Breaking the Legend of [Trusted Computing Group’s Trusted Platform Module] and Vista (BitLocker),” promised to show how computer security based on trusted platform module (TPM) hardware could be circumvented

“We will be demonstrating how to break TPM,” Nitin and Vipin Kumar said in their abstract for their talk that was posted on the Black Hat Web site but was removed overnight Monday.

“The demonstration would include a few live demonstrations. For example, one demonstration will show how to login and access data on a Windows Vista System (which has TPM + BitLocker enabled),” the abstract said.

BitLocker is disk-encryption technology in Microsoft’s Vista operating system that relies on TPM to store keys.

In an e-mail, Vipin Kumar says, “We have pulled back our presentation from … Black Hat. So, we won't be presenting anything related to TPM/BitLocker in Black Hat. . . . We would not like to say anything about the TPM/BitLocker for the time being.” He didn’t respond to inquiries about why the brothers withdrew.

A spokeswoman for the conference was unable to offer more information. “At their request, they are no longer presenting. That is all the info I have,” said the spokeswoman, Nico Sell, in an e-mail.

The conference brings together technically savvy security experts from business, government and the hacking community to discuss the latest security technologies. Frequently, Black Hat briefings become controversial because they point out previously unknown weaknesses in products or technologies.

The Kumars’ promised exploit would be a chink in the armor of hardware-based system integrity that TPM is designed to ensure.

TPM is also a key component of Trusted Computing Group’s architecture for network access control (NAC). TPM would create a unique value or hash of all the steps of a computer’s boot sequence that would represent the particular state of that machine, according to Steve Hanna, co-chair of TCG’s NAC effort.

1 | 2 |  Next >
Comments (6)
Login
Forgot your account info?

Black Hat Orgy-goers uniteBy Schratboy on July 3, 2007, 10:47 amIt's about time the dark underbellied technologists get some character. The predatory nature of the market encourages people to undermine and challenge the orthodoxy...

Reply | Read entire comment

You have a point about the DMCA.By nighthawk808 on July 2, 2007, 9:38 pmLook what happened to Dmitry Sklyarov back in 2001. And this was before the USA became a dictatorship after 9/11; it would only be worse now.

Reply | Read entire comment

Probably not a conspiracyBy Anonymous on June 29, 2007, 2:13 pmThis year, every speaker at Black Hat is required to provide their slides AND a paper about their presentation. Last weekend we were all asked if we would have our...

Reply | Read entire comment

Don't blame them....By Anonymous on June 29, 2007, 1:08 pmThey would probably be thrown in jail after they stepped off of the plane thanks to the wonderful DCMA

Reply | Read entire comment

Not wise to pull this presentationBy Anonymous on June 29, 2007, 11:13 amIt is the most egregious error of any organization to implement the model of 'Security-Through-Obscurity" Pulling this presentation and not deseminating this information...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code