5 ms·
The chips do not have an unique identifier on them. It will be impossible for the manufacturer to look at a chip and then query their db for the encryption key.
by Pharaoh2 11y ago
The chips do not have an unique identifier on them. It will be impossible for the manufacturer to look at a chip and then query their db for the encryption key. At best they will be able to provide all the encryption key that they have produced possibly reducing the search space form 2^128 to ~10B. Also, secure enclave manufacturing process is done is such a way that even the manufacturer does not know what the key is. They don't generate a key for each chip, a natural phenomenon which is truly random is used to burn in the encryption key.
- awqrre 11y agoIf the enclave chips don't have a unique identifier on them after being installed in an Apple device does not mean that they didn't have a temporary identifier... Also, are you saying that even the machines manufacturing them do not know what they are doing ("... secure enclave manufacturing process is done is such a way that even the manufacturer does not know what the key is.")? Sounds a lot like a PR campaign... I would be curious to know how this manufacturing process really works.
- lucaspiller 11y agoIt sounds like the encryption key is generated when the device is running as a combination of the UID and passcode/password, so it's not quite as simple as being able to decrypt everything straight away if you are the manufacturer. Even so, if they do have the UID that greatly reduces the security of the encryption - especially if you are using a short passcode.
- MertsA 11y agoThe idea here is that the secure enclave is a small microprocessor with hardware RNG, encrypted memory, and encrypted storage. The secure enclave generates its own key and it never leaves the chip.