Hmm, que croire? ;-) [provient du premier lien de la news]
"Both [integrity protection and trusted storage] use trusted root certificates as this basis [of their
security guarantees.]" This is a misunderstanding of the TCPA specification. There is no
requirement for certificates at all, to use any TCPA chip function. There doesnt even exist such a
root authority for TCPA in general, or for IBMs currently shipping chips. You can generate
private keys, use them to sign, and decrypt, and seal/unseal data under PCRs, all without any
certificates. The only time a certificate is needed is if you want to be able to prove to a third party
that you have an approved TCPA chip. Most applications do not have this need, and this
certification is not currently supported with IBMs chips. If you want to do an application that
needs such a certificate, the TCPA has an endorsement key that can be used to get a suitable
certificate. The only way this can work is if someone, like the manufacturer, has recorded a given
TCPA chips public endorsement key, and can use this knowledge to certify identity keys from
the given TCPA chip. This is not required, and software access to the endorsement key can be
disabled. There is certainly a privacy aspect of access to the endorsement key, as it uniquely
identifies the platform, and the TCPA specification goes to great lengths to allow for anonymous
certification. The best defense for privacy conscious users is simply to turn off the endorsement
key."
[^] # Re: Controle du système d'information
Posté par tene . En réponse à la dépêche vérifications sur TCPA: je refuse d'avoir des puces et des softs TCPA dans mon ordinateur. Évalué à 4.
"Both [integrity protection and trusted storage] use trusted root certificates as this basis [of their
security guarantees.]" This is a misunderstanding of the TCPA specification. There is no
requirement for certificates at all, to use any TCPA chip function. There doesnt even exist such a
root authority for TCPA in general, or for IBMs currently shipping chips. You can generate
private keys, use them to sign, and decrypt, and seal/unseal data under PCRs, all without any
certificates. The only time a certificate is needed is if you want to be able to prove to a third party
that you have an approved TCPA chip. Most applications do not have this need, and this
certification is not currently supported with IBMs chips. If you want to do an application that
needs such a certificate, the TCPA has an endorsement key that can be used to get a suitable
certificate. The only way this can work is if someone, like the manufacturer, has recorded a given
TCPA chips public endorsement key, and can use this knowledge to certify identity keys from
the given TCPA chip. This is not required, and software access to the endorsement key can be
disabled. There is certainly a privacy aspect of access to the endorsement key, as it uniquely
identifies the platform, and the TCPA specification goes to great lengths to allow for anonymous
certification. The best defense for privacy conscious users is simply to turn off the endorsement
key."