Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Máté

@mkukri@mas.to
mastodon 4.7.2
  • Open on mas.to

firmware troublemaker

75 Followers
13 Following
11 Posts
Joined May 26, 2024
Web:
https://mkukri.xyz
GitHub:
https://github.com/kukrimate/
Open post
Máté @mkukri@mas.to
· 28mo ago

https://mkukri.xyz/2024/06/01/tpm-gpio-fail.html

In this blog post, I describe an attack I've discovered earlier this year that allows system software to forge TPM measurements on some Intel computers.

mkukri.xyz

TPM GPIO fail: How bad OEM firmware ruins TPM security

In this article I demonstrate a software only attack that allows an operating system to set the PCRs of a discrete TPM device to arbitrary values and unseal any secret that uses a PCR based sealing policy (such as disk encryption keys used by unattended unlock TPM FDE schemes).

8
1
9
0
Open post
Máté @mkukri@mas.to
· 22mo ago
Replying to
But one man's backdoor is another's feature. It is the only way to configure the UART GPIOs and to get a coreboot console via the UART (connected to the headphone jack via unpopulated resistors).
5
3
0
0
Open post
Máté @mkukri@mas.to
· 22mo ago
Replying to
The curious should check ec.c here https://review.coreboot.org/c/coreboot/+/83274
review.coreboot.org

Gerrit Code Review

5
2
1
0
Open post
Máté @mkukri@mas.to
· 22mo ago
Replying to
@yuka@fedi.yuka.dev See https://review.coreboot.org/c/coreboot/+/84825 You basically just flash a modified ME image alongside coreboot and that is it.
review.coreboot.org

Gerrit Code Review

3
0
0
0
Open post
Máté @mkukri@mas.to
· 22mo ago
Replying to
@lenzj@fosstodon.org Yes, it can be flashed via an external SPI programmer.
3
0
0
0
Open post
Máté @mkukri@mas.to
· 27mo ago

This weekend's platform security fail, this time courtesy of Dell.
Turns out wiring a PNP transistor between an OS controlled GPIO pin and a manufacturing security override strap is a questionable idea....
The result is write access to the firmware flash, what that can be used for is left as an exercise for the reader.

https://youtube.com/shorts/xKgmSIuisac

4
1
3
0
Open post
Máté @mkukri@mas.to
· 27mo ago
Replying to
@neuroexception@infosec.exchange the bootguard "magic" for it is already publicly committed. coreboot port is WIP
4
1
1
0
Open post
Máté @mkukri@mas.to
· 22mo ago
Replying to
@alicela1n@social.treehouse.systems BootGuard on that machine is not yet broken.
2
0
0
0
Open post
Máté @mkukri@mas.to
· 27mo ago

ThinkPad T480 coming to #coreboot

mas.to

mas.to

2
0
1
0
Open post
Máté @mkukri@mas.to
· 25mo ago

@elly@donotsta.re How new is the new in that? T480 will be ported when I overcome general burnout and general reverse engineering induced misery https://review.coreboot.org/c/coreboot/+/83274

donotsta.re

Akkoma

1
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 05:12:06 UTC