Security
The attacks we defeat, and the ones we name plainly.
Most abuse runs on software-only attacks that cost cents. Those stop outright. Everything above that tier gets more expensive than what it steals — and where hardware can't help at all, we say so.
Coverage
What we stop, and where it works.
Every attack we defend against, grouped by what it costs the attacker to run — and which of your platforms it's covered on.
| Attack | Costs them | WindowsTPM 2.0 | LinuxTPM 2.0 | macOSSecure Enclave | AndroidKey Attestation | iOSApp Attest |
|---|---|---|---|---|---|---|
Software-onlycents per fake Cloud VMs, virtual TPMs and software emulators. Where essentially all real-world abuse volume lives — and where a hardware check stops it outright. | ||||||
| VM-spawn-and-discard account farming | $0.01–$0.10 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Cloud-vTPM account farming (NitroTPM / Azure / GCP) | $0.01–$0.50 | ✓ | ✓ | – | – | – |
| swtpm emulator account farming | ~$0 | ✓ | ✓ | – | – | – |
| CAPTCHA solver-farm bot signup | $0.001–$0.005 | ✗ | ✗ | ✗ | ✗ | ✗ |
| Anti-detect browser + residential proxy | $0.20–$1 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Email/phone churn signup | $0.05–$0.50 | ✗ | ✗ | ✗ | ✗ | ✗ |
Firmware exploitshours of work Known flaws in a chip's firmware, limited to the shrinking pool of unpatched machines. | ||||||
| TPM-Fail timing side-channel | ~$0 | ✓ | ✓ | – | – | – |
| ROCA on Infineon RSA | compute only | ✓ | ✓ | – | – | – |
| faulTPM voltage glitching | $200 rig + hours | ✓ | ✓ | – | – | – |
| CVE-2025-2884 OOB read (Pluton/fTPM) | ~$0 | ✓ | ✓ | – | – | – |
| TPM-Genie hardware interposer | $30 + skill | ✓ | ✓ | – | – | – |
Real device farms$30–$200 each The honest cost floor. The chips are genuine, so the attacker buys hardware — and buying in bulk leaves a cluster you can see. | ||||||
| Refurb device farm | $30–$200 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Burner-phone-service farm | $40–$100 | ✓ | ✓ | ✓ | ✓ | ✓ |
Physical tampering$200+ and hands on the machine Only possible where the chip is a separate, removable part. | ||||||
| TPM chip swap (discrete TPM only) | $40–$200 | ✓ | ✓ | – | – | – |
| Header-pin TPM module replacement | $20–$40 | ✓ | ✓ | – | – | – |
Silicon extractionsix figures per device Nation-state lab work. Off the table for commercial abuse. | ||||||
| Decapping / electron microscopy | $50K–$200K | ✓ | ✓ | ✓ | ✓ | ✓ |
Replay & relayfree, if it works Reusing a genuine device's proof somewhere else. | ||||||
| Cloud-cuckoo relay | ~$0 | ✓ | ✓ | ✗ | ✗ | ✗ |
| Physical-cuckoo relay | ~$0 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Quote replay | $0 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Session-binding bypass | $0 | ✓ | ✓ | ✓ | ✓ | ✓ |
Not solvable by hardware— Named plainly because pretending otherwise is worse than saying it. These need layered defenses, not attestation. | ||||||
| Compensated real users ('device mercenaries') | $1–$50 | ✓ | ✓ | ✓ | ✓ | ✓ |
| Account-takeover post-enrollment | variable | ✗ | ✗ | ✗ | ✗ | ✗ |
| Device theft / borrowed device | varies | ✗ | ✗ | ✗ | ✗ | ✗ |
| Supply-chain compromise of manufacturer CA | nation-state | ✗ | ✗ | ✗ | ✗ | ✗ |
| Insider threat (Root Herald operator) | n/a | ✗ | ✗ | ✗ | ✗ | ✗ |
Coverage is derived, not asserted per cell: each of our ten checks either exists on a platform or doesn't, and an attack counts as stopped where every check that defeats it is available. Windows and Linux run full TPM 2.0 attestation; macOS, Android and iOS use their platform's own hardware attestation, which has no boot-measurement log — that gap is what most of the ~ marks are.
Explicitly out of scope
What we don't claim to solve
- One-human-one-device with bad intent. We bind devices to identities; identity behaviour is your policy call.
- In-person social engineering. A real user, a real attestation, attacker-coached.
- Account takeover after enrollment. Step-up MFA and session management belong in your stack.
- State-level adversaries. Outside the threat model for any commercial SaaS.
- Supply-chain compromise of manufacturer PKI. Detection and response only — the risk every PKI-based system carries.
- Insider threat at Root Herald. SOC 2 controls, in progress. Not protocol.
Catalogue
Every threat, with its cost tier, defence layers and residual risk.
Tier 1 — Software-only attacks
Bots, throwaway cloud servers, software chip emulators. Stopped outright: the proof does not check out.
T-101VM-spawn-and-discard account farming$0.01–$0.10 · Infinite
- Mechanism
- Rent cloud VMs, run signup with each as a fresh identity. Cost ~$0.005/hr per instance.
- Defence
- L2, L3, L9
- Residual
- None at the cryptographic layer. Attacker must escalate.
- Real-world
- LayerZero's 803K excluded wallets were largely cloud-VM clusters.
T-102Cloud-vTPM account farming (NitroTPM / Azure / GCP)$0.01–$0.50 · Infinite
- Mechanism
- Cloud VM has a real virtual-TPM 2.0 producing a structurally valid attestation. Bypasses naive 'did they have a TPM' checks.
- Defence
- L2, L3, L4, L9
- Residual
- None under strict-hardware. Under cloud-permissive policy, IID cross-validation closes it.
T-103swtpm emulator account farming~$0 · Infinite
- Mechanism
- Userspace swtpm emulator produces TPM 2.0 commands and certs chaining to swtpm-localca.
- Defence
- L2, L3, L9
- Residual
- None.
- Real-world
- SUSE virt guide documents emulated TPM reports manufacturer 49424d00 regardless of host.
T-104CAPTCHA solver-farm bot signup$0.001–$0.005 · Infinite
- Mechanism
- Solver farms defeat CAPTCHA at $1–$3 / 1000 solves.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- Out-of-scope for Root Herald directly — but composes: solver-farm wins CAPTCHA, fails attestation.
T-105Anti-detect browser + residential proxy$0.20–$1 · Infinite
- Mechanism
- Rotated browser fingerprints + residential IP egress. Defeats FingerprintJS / Castle / DataDome.
- Defence
- L8 (partial), L10
- Residual
- None when paired with attestation.
T-106Email/phone churn signup$0.05–$0.50 · Infinite
- Mechanism
- Throwaway emails, SIM farms, virtual-number services.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- Out-of-scope alone; composes with attestation.
Tier 2 — Firmware-vulnerability attacks
A known flaw in a chip's firmware, on the shrinking pool of un-patched machines. Boot-fingerprint drift is flagged and revoked bootloaders honoured; there is no blocklist of vulnerable firmware.
T-201TPM-Fail timing side-channel~$0 · Bounded
- Mechanism
- Timing side-channel against Intel fTPM ECDSA. Recovers private keys in minutes locally.
- Defence
- L8 (partial), L9
- Residual
- Root Herald ships no known-bad firmware deny-list. The compensating controls are change-detection against a customer's known-good PCR reference values (a device whose measured boot no longer matches its allow-listed reference is flagged) plus dbx bootloader revocation.
- Real-world
- tpm.fail PoC; CVE-2019-11090.
T-202ROCA on Infineon RSAcompute only · Bounded
- Mechanism
- Coppersmith's attack on Infineon RSA generation flaw. ~760K still-vulnerable May 2025.
- Defence
- L3 (partial), L8 (partial), L9
- Residual
- Estonian national ID recall (2017) — 750K cards re-keyed.
- Real-world
- CVE-2017-15361; weaponized PoCs exist.
T-203faulTPM voltage glitching$200 rig + hours · Bounded
- Mechanism
- Voltage-glitching against AMD fTPM on Zen 2/3. ~$200 hardware, hours per chip.
- Defence
- L8 (partial), L9
- Residual
- Requires physical access; bounds to ≈ Tier 3.
- Real-world
- USENIX / Black Hat USA 2023.
T-204CVE-2025-2884 OOB read (Pluton/fTPM)~$0 · Bounded
- Mechanism
- OOB read in TCG TPM 2.0 reference. Patched in AGESA 1.2.0.3e.
- Defence
- L9
- Residual
- Large unpatched OEM tail through 2026. There is no CVE/firmware-rev deny-list; the policy-layer control is change-detection against known-good PCR reference values plus dbx revocation.
T-205TPM-Genie hardware interposer$30 + skill · Bounded
- Mechanism
- Hardware interposer on LPC bus intercepts and modifies commands.
- Defence
- L7, L8
- Residual
- Bounds to Tier 3 + labor; uneconomic for most use cases.
Tier 3 — Physical device farm
The cost floor. The chips are real, so the attacker buys real hardware; each chip is unique and bulk purchases cluster.
T-301Refurb device farm$30–$200 · Bounded
- Mechanism
- Buy hundreds of cheap real devices, each a unique valid attestable identity. Logistics-bound.
- Defence
- L8, L10
- Residual
- The honest cost floor: capital-bound and detectable, not impossible. Six-figure airdrops still clear this bar.
- Real-world
- Southeast Asia click-farm operations photographed publicly.
T-302Burner-phone-service farm$40–$100 · Bounded
- Mechanism
- Many 'fresh' phones used briefly, then retired.
- Defence
- L8, L10
- Residual
- Same as T-301.
Tier 4 — Physically swapping the chip
Only on machines with a removable TPM. Most modern PCs bake the chip into the CPU.
T-401TPM chip swap (discrete TPM only)$40–$200 · Bounded
- Mechanism
- Desolder existing discrete TPM, solder in a new $5 Infineon SLB 9672, mint fresh EKpub.
- Defence
- L8, L10
- Residual
- Only applies to discrete TPMs — ~70% of modern Windows uses in-CPU Pluton/PTT/fTPM.
T-402Header-pin TPM module replacement$20–$40 · Bounded
- Mechanism
- Enthusiast motherboards with TPM header pins allow swap without soldering.
- Defence
- L8, L10
- Residual
- Same shape as T-401.
Tier 5 — Extracting a key from the silicon
Lab work, one device at a time. Outside any commercial abuse case.
T-501Decapping / electron microscopy$50K–$200K · Singular
- Mechanism
- Physical attacks against the TPM die.
- Defence
- L8 (partial), L10
- Residual
- Not on the cost ladder for any commercial abuse case.
Relay attacks
Reusing a real device's proof elsewhere. Cloud relays are bound to one instance; physical relays gain nothing because each proof is tied to one chip.
T-601Cloud-cuckoo relay~$0 · Infinite if it works
- Mechanism
- Harvest a real NitroTPM attestation from one EC2, replay from a different cloud instance.
- Defence
- L4
- Residual
- None when RequireCloudCrossValidation = true. Default for cloud-permissive policy.
T-602Physical-cuckoo relay~$0 · Infinite attempts, 1 identity
- Mechanism
- Script N fresh signup sessions, pipe each nonce to one real TPM, collect N quotes.
- Defence
- L8
- Residual
- Attacker is pushed back to Tier 3 (acquire more real chips). The 'cheap relay shortcut' doesn't exist.
T-603Quote replay$0 · Singular
- Mechanism
- Capture a valid attestation quote, re-submit later.
- Defence
- L5
- Residual
- None within the quote-freshness window.
T-604Session-binding bypass$0 · Singular
- Mechanism
- Use a valid verdict in a context other than the one it was produced for.
- Defence
- L5, L9
- Residual
- Depends on RP integrating correctly; libraries get this right by default.
Out of scope for hardware alone
A real person paid to sign up, a stolen account, a stolen device, a compromised manufacturer, a rogue insider.
T-701Compensated real users ('device mercenaries')$1–$50 · Bounded
- Mechanism
- Pay N real users $X each to perform a real attestation from their real devices.
- Defence
- L10
- Residual
- Honest disclosure. Hardware attestation alone cannot stop this. Layered defense (hardware floor + behavioral) is the strategy.
- Real-world
- Documented in LayerZero's airdrop retrospective.
T-702Account-takeover post-enrollmentvariable · Bounded
- Mechanism
- Compromise a legitimate user's session post-enrollment.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- Out-of-scope; step-up MFA / CAEP / session-management is the customer's stack.
T-703Device theft / borrowed devicevaries · Singular
- Mechanism
- Legitimate hardware under attacker's physical control.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- A user can mark a device stolen; the per-tenant ban list then rejects further attestations from it.
T-704Supply-chain compromise of manufacturer CAnation-state · Singular
- Mechanism
- Attacker compromises an Infineon/ST/Nuvoton/Intel/AMD/Microsoft CA and mints arbitrary EK certs.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- Detection + response only.
T-705Insider threat (Root Herald operator)n/a · Singular
- Mechanism
- Root Herald employee exfiltrates EKpub data or forges verdicts.
- Defence
- Out of scope at the cryptographic layer.
- Residual
- SOC 2 controls (in progress, not yet certified); not protocol-level.
Price every attack out of profitability.
Free up to 1,000 active devices a month, no card.