0

Is fTPM more secure than a real TPM module when using Bitlocker? As far as I know, you should enable pre-boot authentication if you use a TPM module that is plugged separately onto the motherboard to prevent possible reading / sniffing of the key from the TPM.

Here and here it is said that it is much more difficult or even impossible to read the key during the boot process when using fTPM, because there is no open connection (bus) between TPM and processor. Thus, in my opinion, one would not need a pre-boot authentication when using fTPM or do I see it wrong?

I am interested in the relatively normal protection of my hard drives and data, for example, if something is stolen or who knows for whatever reason the police is at the door.

Therefore the following would be sufficient to use Bitlocker for such cases:

  • Use fTPM (without pre-boot authentication)
  • Put PC to hibernate (write RAM to Disk) or complete power off and not into sleep / energy saving mode to prevent reading the key from RAM

This should be safe enough against normal attacks (especially reading / sniffing of the key) or am I wrong? Of course you can cool down the running PC or RAM, etc. massively to be able to read out the data longer, but these are all scenarios that are rather used under laboratory conditions or in really extreme cases (if at all).

As i know without pre-boot authentication the key will be released immediately and with pre-boot authentictaio enbaled the key will be released only when the PIN is entered. So as fTPM implementation is much faster and harder to sniff, i think when using fTPM pre-boot authentication is not really needed or am i wrong?

Opa114
  • 101
  • 1
  • There may be one situation where an fTPM is more secure: if you compare it to am TPM 1.2 or 2.0 on Windows 10. As known [known by the sniff attack in the TPM bus](https://pulsesecurity.co.nz/articles/TPM-sniffing) Windows 10 does not use encrypted communication to the TPM so a fTPM would be more secure as it should be way more difficult to sniff communication... – Robert Jul 11 '22 at 20:57
  • So Windows 11 uses encrypted communication? Any Sources for this? That's the main point i'm interested in - more secure against sniff attacks. – Opa114 Jul 12 '22 at 07:26

0 Answers0