Windows 10: RSA Keys Generated by Infineon TPMs are Insecure

Discus and support RSA Keys Generated by Infineon TPMs are Insecure in Windows 10 News to solve the problem; Lenovo Security Advisory: LEN-15552 Potential Impact: RSA keys generated by the Infineon TPM using certain firmware levels are insecure Severity:... Discussion in 'Windows 10 News' started by Brink, Oct 23, 2017.

  1. Brink
    Brink New Member

    RSA Keys Generated by Infineon TPMs are Insecure


    Read more: RSA Keys Generated by Infineon TPMs are Insecure

    :)
     
    Brink, Oct 23, 2017
    #1
  2. Nick37ZR Win User

    Windows update fails repeatedly to install 1709

    I get following message:

    You need to remove these apps yourself and then press REFRESH: INFINEON TPM Professional Package

    I search my C Drive for Infineon and find two Infineon Folders (one in AppData/Roaming and one C:/Program Data) plus a dll file "Infineon.SecurityPlatform.Reporting"

    The folders contain several subfolders and files, but none named TPM Professional package.

    What should I do? Delete all Infineon folders/files? Or some of them? Which?

    Then, assuming 1709 installs OK, what about Infineon TPM, will the PC remain without Infineon TPM??

    Or should I ignore completely the 1709 Update? Is it essential?

    Thank for any help

    Cheers

     
    Nick37ZR, Oct 23, 2017
    #2
  3. Nick37ZR Win User
    Repeated Failure with Windows 10 Update to 1709

    Q: Remove Infineon TPM for Winsows Update to install 1709

    I get following message:

    You need to remove these apps yourself and then press REFRESH: INFINEON TPM Professional Package

    I search my C Drive for Infineon and find two Infineon Folders (one in AppData/Roaming and one C:/Program Data) plus a dll file "Infineon.SecurityPlatform.Reporting"

    The folders contain several subfolders and files, but none named TPM Professional package.

    What should I do? Delete all Infineon folders/files? Or some of them? Which?

    Then, assuming 1709 installs OK, what about Infineon TPM, will the PC remain without Infineon TPM?? Are the Infineon files really needed on the C-Drive for the system to function OK?? If so, Should I save the Infineon Folders to
    a pen drive, then delete them from the C Drive, run the 1709 Update and (assuming it succeeds) then, if I really must have the Infineon in my C drive, shift the folders back to where they were before in the C Drive?

    Or should I ignore completely the 1709 Update? Is it essential?

    Thank for any help

    Cheers

     
    Nick37ZR, Oct 23, 2017
    #3
  4. Tonyb Win User

    RSA Keys Generated by Infineon TPMs are Insecure

    I'm waiting on a update from infineon as mine is a infineon chip but i can't find any updates for my firmware at MSI website as its msi but the chip is infineon, i sent infineon a email have yet to hear back as to how i get it updated.
     
    Tonyb, Oct 24, 2017
    #4
  5. no1yak Win User
    Asus use the Infineon chip in their TPM's and windows is telling me that it's not secure. I won't hold out much hope of Asus up dating the bios as the number of people that are using TPM's is probably quite small - but one lives in hope.
     
    no1yak, Oct 24, 2017
    #5
  6. sygnus21 Win User
    This news article was generated by my post here Infineon TPM Modules generating insecure RSA Keys - Windows 10 Forums. In that post I tell you how to check which TPM module you have and where to get the fix from if you're a Lenovo notebook user.

    BTW if you are a Lenovo notebook user and opted to be notified on new updates via e-mail, you should have gotten a notice on this already. See my link for more details.

    With that for those owning laptops and have an Infineon chip check the manufacturer's site for an update & fix.
     
    sygnus21, Oct 24, 2017
    #6
  7. Tonyb Win User
    I wish its a home built system with MSI mainboard and MSI TPM chip by infineon as in the TPM.MSC it shows it as IFX and i pulled it out of the pc an its a Infineon TPM 1.2 . not sure how i can get the update for it as infineon does not provide them to end users and MSI has nothing about it on there website.
     
    Tonyb, Oct 24, 2017
    #7
  8. sygnus21 Win User

    RSA Keys Generated by Infineon TPMs are Insecure

    I edited my post while you were quoting me so they no longer align. Sorry.

    Anyway, In your case I have no answer other than to perhaps point MSI tech support to the news article here, or call MSI personally and see what they have to say. Unfortunately the information from my article and the one here is generated by Lenovo, so I can't say how other vendors may be dealing with the issue - or if they even view this as an issue.

    The other thing is how far back are we going here - are these new, old, or both chips. Are they only TPM 1.2, 2.0, or both? Again, we only see what Lenovo is doing, so....
     
    sygnus21, Oct 24, 2017
    #8
  9. Tonyb Win User
    Tonyb, Oct 24, 2017
    #9
  10. sygnus21 Win User
    I was just about the post that link to you when I saw your post *Smile

    Anyway cleaned up this is the same link - TPMupdate - Infineon Technologies

    It looks like this issue mainly affects notebooks not desktops, but....
     
    sygnus21, Oct 24, 2017
    #10
  11. Tonyb Win User
    yeah seen that going to take your advice though and give MSI a phone call *Smile
     
    Tonyb, Oct 24, 2017
    #11
  12. sygnus21 Win User
    Question - Is this a desktop or laptop?

    I'm not aware of any store bought motherboards coming with TMP chips installed. Every motherboard I bought never came with one. This includes 3 Gigabyte boards, 3 Intel boards, and a couple of Abit boards.

    All that said, if this is a custom desktop build, did your board actually come with a TPM chip or did you add it later? If you purchased it separately, you may be on your own.
     
    sygnus21, Oct 24, 2017
    #12
  13. Tonyb Win User

    RSA Keys Generated by Infineon TPMs are Insecure

    it was a added on chip on my home built system i bought it with the mainboard from MSI . it's a desktop.
     
    Tonyb, Oct 24, 2017
    #13
  14. no1yak Win User
    sygnus21
    "I'm not aware of any store bought motherboards coming with TMP chips installed. Every motherboard I bought never came with one. This includes 3 Gigabyte boards, 3 Intel boards, and a couple of Abit boards."

    My Asrock Gaming K6 has an on board TPM, fortunately it's an Intel chip. My Asus has the plug in 14-1 pin, so I'm not expecting Asus to do much. Although the TPM is made by Asus and has their name on it.
     
    no1yak, Oct 25, 2017
    #14
  15. sygnus21 Win User
    I didn't think it was impossible, just rare. That said, yes most newer boards will have the 14 pin plugin, my last two boards have one. In fact I bought a TPM for my Z170 board and just moved it over to my active Z270 Gigabyte board. Turns out even though the chip has Gigabyte's name on it, it's an Infineon chip. I used Lenovo's firmware updater check the chip and it say's it doesn't need the update, but I'm not sure I should trust the updater.
     
    sygnus21, Oct 25, 2017
    #15
Thema:

RSA Keys Generated by Infineon TPMs are Insecure

Loading...
  1. RSA Keys Generated by Infineon TPMs are Insecure - Similar Threads - RSA Keys Generated

  2. insecure system?

    in Windows 10 Gaming
    insecure system?: I recently found that my financial info had been used and now I find that I can't be reimbursed.I felt something was up for the last year or two because I can't get a fresh install to boot in normal mode.But the reason I'm here is i've found that my pci lock was not checked...
  3. insecure system?

    in Windows 10 Software and Apps
    insecure system?: I recently found that my financial info had been used and now I find that I can't be reimbursed.I felt something was up for the last year or two because I can't get a fresh install to boot in normal mode.But the reason I'm here is i've found that my pci lock was not checked...
  4. insecure system?

    in AntiVirus, Firewalls and System Security
    insecure system?: I recently found that my financial info had been used and now I find that I can't be reimbursed.I felt something was up for the last year or two because I can't get a fresh install to boot in normal mode.But the reason I'm here is i've found that my pci lock was not checked...
  5. Adb, USB debugging, and RSA Keys

    in Windows 10 Ask Insider
    Adb, USB debugging, and RSA Keys: Hi! 2 days ago, my phone's screen passed away, so I coudn't controll the screen or even see it, luckly I had USB Debugging enabled and my computer saved as a safe PC (before all of this I clicked on "remember this PC" to prevent this things), well, I could access to the...
  6. RSA SecurID sign-in

    in Windows 10 Ask Insider
    RSA SecurID sign-in: Apple's iPhone will be able to use such an accessory or app to log in to Windows 10. At its Ignite conference this week, Microsoft said iPhone owners can use specific RSA SecurID authenticator tools on their devices to unlock Windows 10 PCs. RSA uses gesture detection on the...
  7. Infineon tpm professional package

    in Windows 10 Installation and Upgrade
    Infineon tpm professional package: Hi, I am failing to upgrade to Windows 10 because of Infineon tpm professional package https://answers.microsoft.com/en-us/windows/forum/all/infineon-tpm-professional-package/05e7f61d-f1a0-4dde-a367-84f22919320d
  8. Infineon TPM Professional Package

    in Windows 10 Installation and Upgrade
    Infineon TPM Professional Package: Whenever I attempt to a Windows 10 upgrade, it fails and I am instructed to remove the "Infineon TPM Professional Package" app (this is always listed twice in the dialog box). I cannot locate any Infineon app (have searched "Infineon" and "Infineon TPM"). How can I resolve...
  9. Insecure Guest Logons

    in Windows 10 Network and Sharing
    Insecure Guest Logons: Could Somebody tell me If I enable insecure guest logons, Is that Ok? https://answers.microsoft.com/en-us/windows/forum/windows_10-networking/insecure-guest-logons/eb39b0a8-98c3-45c1-ade5-442bf96ce96f
  10. Infineon TPM Modules generating insecure RSA Keys

    in Windows 10 Drivers and Hardware
    Infineon TPM Modules generating insecure RSA Keys: FYI... I get emails for updates for my Lenovo ThinkPad notebook. That said, I got one this morning alerting me that some Lenovo notebooks using Infineon TPM modules are generating insecure RSA keys - RSA Keys Generated by Infineon TPMs are Insecure Anyway, the link...