posted in Technology
The security co-processor in many CPUs is insecure
www.heise.de/en/news/The-security-co-processor-in-many-CPUs-is-insecure-11411956.htmlposted in Technology
The security co-processor in many CPUs is insecure
www.heise.de/en/news/The-security-co-processor-in-many-CPUs-is-insecure-11411956.htmlWell that’s OK; we recently discovered that things like passkeys usually aren’t using the TPM anymore anyway. Most stuff stored in there can be routed around via tokens stored on main storage.
Though the FIDO2 has security level 1 to 3 and anything above lvl 1 can basically not be fulfilled by open hardware keys, since level 2 requires documented supply chains and expensive certificates.
Source: a journey with my govt. login portal.
Replying to @adespoton@lemmy.ca
I’m honestly amazed by this. Passkeys were the touted solution to all our human password problems. How is it that something so critical went unnoticed until recently?
You’d think this would be something that gets caught before release. What went wrong?
IIRC, the Passkey spec did not specify the use of specialized hardware for key storage. So if this a case where people chose convenience over security without realizing they were making the tradeoff?
That would still be phenomenal. Who leads these sort of things and why is such a blatant issue unnoticed until most of us are affected?
It doesn’t matter how good a plan is if we can’t follow it. So what stops this issue from continuing to plague the next “great” solution to password management?