49 ms·
Great piece. Get thee to a "Secure Enclave" supported device, everyone.
by jeffehobbs 11y ago
Great piece. Get thee to a "Secure Enclave" supported device, everyone.
- venomsnake 11y agoOr any rooted android. Good luck in defeating LUKS. No custom firmwares will help them.
- feld 11y agoa rooted android is probably easiest to own over the air with a push notification, so yeah, that's a great idea! NOT
- venomsnake 11y agoA powered down device rarely has that vulnerability.
- paraxisi 11y agoA powered down device isn't exactly terribly useful.
- 16bytes 11y agoYou can't send a powered down phone a push notification for post-hoc analysis. You would have had to know the target and push a vulnerability beforehand, which wouldn't have helped in this case.
- feld 11y agoSo power it on? It will still boot with encryption. Isn't Android encryption is an extension of ext4 and only protects some data. It's not full disk / LUKS last I knew.
- TACIXAT 11y agoCould you expand a little on what you're referring to? Is this a specific vulnerability?
- scintill76 11y agoMake sure you set high enough LUKS master key iteration counts, and/or very complex password, so that they can't image the LUKS header and brute-force your passphrase off-device.
- st3v3r 11y agoA rooted android is even less secure.
- venomsnake 11y agoIf you say so https://blog.torproject.org/blog/mission-impossible-hardening-android-security-and-privacy https://blog.torproject.org/blog/mission-impossible-hardenin...
- HillRat 11y agoJohn Kelley (@johnhedge), former Apple security engineer, says that Secure Enclave isn't protected against that kind of tampering, so that's not a solution, either. Until manufacturers start going to embedded HSMs, anyway.