Panel: Trusted Platform Module
February 24, 2014, RSA Conference, Trusted Computing Group, San Francisco—A panel considered the challenges in implementing TPM. Paul Roberts from The Security
Ledger moderated the panel. Panelists were Monty Wiseman from Intel, Dustin Ingalls from Microsoft, and Gal Shpantzer from SANS.
The industry has reached an inflection point in the technology, moving towards greater adoption and implementation. This is a change from last year.
Wiseman noted that there is greater understanding due to the changes in the TPM specifications. The industry still has to evangelize and encourage adoption.
Implementation of Windows 8 is a change form previous releases?
Ingalls noted that the Bit Locker software was limited, so they pushed security into the hardware. The hardware is moving towards a general purpose security device that is simple, easy to use, robust, and protects the system. TPM makes many security settings the default.
Standards and integration levels need more tools?
Wiseman commented that TCG development software stack had limits with the earlier revisions. Moving to release 2.0, due out later this year, will bring about more open source tools that will ease development.
Shpantzer added that the latest version is back compatible with the earlier revisions.
Wiseman declared that it was hard to code SHA-1 into TPM, but at SHA-256, they needed to change the specification to allow for a bigger byte store.
Ingalls joined in that they decode a UFEI secure boot that has been verified with TPM. This step is critical to overall security.
APT and other attacks try to get into the boot stage, but TPM sets a baseline for boot code?
Wiseman stated that TPM protects the data but an APT can infect that data and appear as a bad sense bit. The TPM informs the operator that there has been a change in the software posture of the machine.
Shpantzer declared that apps in the cloud and in virtualized computers are getting other attacks. The malware still works in the cloud as if coming in the front door. The traditional attacks still work. new cloud-focused attacks are starting, but they are at the next layer of attention.
Microsoft tools and other security still has TPM as more resilient?
Ingalls responded that TPM is a critical tool, and the base for confirming that the end point is ok. If the bios, OS, and security software are ok at boot, then the end point can have access.
Need to identify malware software better?
Ingalls stated that a perimeter-based defense is less effective with BYOD, but a change from prevent to detect and isolate can contain more attacks. Stuff will get in, but TPM allows better detection of changes, especially for APTs.
Datacenters and endpoints are changing technology from a single end point to networks like the cloud. How does TPM fit?
Shpantzer commented that there are 1B TPM devices built for enterprise work with provisioning, administration, etc., and all are moving towards a more democratized system. BYOD is here to stay as is browserization of apps. This greater acceptance is seen in Chromebooks, where the internal software is checked for validation before the host will connect. The ARM trustzone has similar leverage with the hardware to confirm code integrity.
Apple?
Shpantzer answered, indirectly, but they are not a member of TCG.
Wiseman added that the cloud distributes the workload across the network. A single endpoint allows control of that machine, but virtualization means a virtualization layer that is not machine specific. As a result, you cannot confirm an operating machine, and need hardware to confirm locality and access to data. The Open Software Stack is a trusted environment that is virtual machine clean, and tied to the hardware.
Ingalls agreed while noting that for privacy and localization concerns, especially in the EU, needs to prove to an auditor that the data exist in an approved space. It is possible to work in the cloud with data-specific localization.
Internet of Things and security awareness? Self-assembled networks and configuration have issues, while authentication and security don’t exist. You will need a hardware root of trust which may move TPM to IoT?
Ingalls considered that this issue focuses on the value of TPM and the value of identity. Having a hardware advised identity in the rush to mobile, premium services, and electronic credit cards helps to manage security. Hardware bound endpoints are driving IoT to include hardware-bound attestation.
Wiseman added that TPM and TCG standards are proven and have demonstrated value. Any implementation can use a subset of the full TPM pototcols.
The hardware can change while the protocols remain stable?
Shpantzer indicated that medical devices need more attention to security, especially for wireless updates.
Magically find data while TPM protects it?
Wiseman suggested that the data be encrypted prior to VPN and use the TPM protocol to authorize access.
Shpantzer endorsed this and for networks like Amazon cloud, to keep the keys in-house and just have the provider handle the hardware.
Binding data to apps?
Ingalls noted an evolution in investments for code authentication and putting more in the stack. Win8 has a secure boot for end-to-end transfers.


