Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Compliance is Less Expensive than Data Breaches - Gartner | Main | Getting Details on Vulnerability Isn't Always Easy »

Trusted Computing Platform Vulnerability Presentation Blocked at Black Hat

Once again an important Black Hat presentation has been blocked. This time it's the planned talk by Nitin and Vipin Kumar of NV Labs. The NV Labs site has some information on the company's research into bypassing TCP and Vista BitLocker. Here's an excerpt from one of their Web postings:

The attack procedure (TPMkit) involves an attack on the TPM.TPMkit lets you overcome technologies such as Vista's BitLocker.TPMkit also bypasses remote attestation and thus, will allow to connect over Trusted Network Connect(TNC)(although the system might not be in Trusted state.). TPMkit bypasses the security checks mentioned (in the above paragraphs) and thus, you will never know that you are using a compromised or changed system.

With 150 million TCP devices already shipped and no easy way to patch them without calling into question the whole idea of hardware based integrity checks, it's important to know what vulnerabilities exist. Looks like we won't be getting the details from Black Hat.

ComputerWorld tried to get details on why the talk was cancelled but came up empty handed.

In an e-mail, Vipin Kumar says, "We have pulled back our presentation from ... Black Hat. So, we won't be presenting anything related to TPM/BitLocker in Black Hat. ... We would not like to say anything about the TPM/BitLocker for the time being." He didn't respond to inquiries about why the brothers withdrew.

A spokesman for the conference was unable to offer more information. "At their request, they are no longer presenting. That is all the info I have," said the spokesman, Nico Sell, in an e-mail.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/341

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net