7 ms·
Qualcomm KeyMaster keys extracted directly from TrustZone
- gruez 10y agoHow would this be patched? I'm assuming that this will require ucode/hardware patching as trustzone is implemented in hardware?
- Namidairo 10y agoMy understanding was that there's a signed TrustZone binary that's more or less an ELF that runs in secure mode.
- runholm 10y agoIf TrustZone itself has a bug, that would require a hardware patch. Luckily it seems that this bug was an issue with the code running on the chip. With TrustZone, some code is running in the secure domain and can read or write to both secure and non-secure memory. You need to find some bug in the secure code to "trick" the secure code into copying data from secure memory to non-secure memory.
- modeless 10y agoWhat is TrustZone being used for in practice?
- iliketosleep 10y agoit's used for stuff like trusted firmware, and easily leads to devices being bricked
- HappyTypist 10y agoiPhones secure enclave, full disk encryption, Touch ID, etc. likewise on android.
- JumpCrisscross 10y agoSource?
- NEDM64 10y agoHe's a troll. iPhones don't use it. They don't use Qualcomm SOC's.
- deleted 10y ago[deleted]
- runholm 10y agoNote that TrustZone is not a Qualcomm technology, but rather an ARM technology. Apple could have gone with TrustZone in their SOC. (But yes, he is a troll and this whole case has nothing to do with Apple).
- msbarnett 10y agoNit: TrustZone isn't a Qualcomm technology, but KeyMaster is Qualcomm software built on top of it (and that appears to be where this break lies).
- icelancer 10y ago>iPhones nah
- willvarfar 10y agoApologies to the uninformed downvoters :( TrustZone is an ARM thing, and the iPhone Secure Enclave is indeed built on TrustZone. Apple do not use Qualcomm and this a Qualcomm-specific bug. But Apple do use their own modded TrustZone.
- james_a_craig 10y agohttp://www.apple.com/business/docs/iOS_Security_Guide.pdf http://www.apple.com/business/docs/iOS_Security_Guide.pdf page 7. Despite widespread rumour to the contrary, the secure enclave on iPhones is a separate core, not just TrustZone on the main CPU.
- zurn 10y agoDRM for example, see this older post where a bug in Qualcomm's DRM software enabled full system compromise: http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html http://bits-please.blogspot.com/2016/05/qsee-privilege-escal...
- michaelt 10y agoTo provide the Android hardware-backed keystore [1] If it's present, this is used by apps like 'Google Authenticator' and 'Symantec Vip access' to store credentials in such a way that they can't be copied off the device or backed up. When this technology works perfectly, the idea is if you have a short passcode and someone steals your phone, they can't extract the encrypted data and brute-force the passcode without an electron microscope and a team of engineers. Unfortunately, it can also be used for user-hostile applications like providing DRM and preventing backups and rooting. [1] https://source.android.com/security/keystore/ https://source.android.com/security/keystore/
- jkirsteins 10y agoDo you have a link documenting that Google Authenticator (or Symantec) uses it?
- michaelt 10y agoI'm reasonably certain about Symantec Vip Access, because I've decompiled it (download apk 3.1.3 -> dex2jar -> jd-gui). Class named ṝ method named ˎ make calls that look like calls to the android key store. Hard to be 100% certain because the code is obfuscated though. I was wrong about Google Authenticator. I assumed it was the same as Symantec because of all the people online complaining about being unable to back up their credentials.
- low_key 10y agoThis is not used by Google Authenticator. GA just keeps the parameters in an sqlite database. It doesn't do much to protect them.
- guimarin 10y agoI hope there is a way to patch this remotely. TrustZone is on quite a few devices today.[1] If it's not, well, uhh, yeah this is kind of a problem. 1. http://www.arm.com/products/processors/technologies/trustzone/ http://www.arm.com/products/processors/technologies/trustzon...
- dogma1138 10y agoKeymaster is a Key Management application that runs "ontop" of TrustZone this doesn't mean that TrustZone or even QM's (hardware) implementation of TrustZone is flawed. It's more likely than not just a flaw within Keymaster itself, or within the Trustzone Kernel which means that this can effectively be patched, this isn't the first time vulnerabilities like this have been identified[0] (same author) and previous issues have been patched. For anyone who wonders TrustZone is a Trusted Execution Environment (TEE) technology for ARM CPU's the more known equivalent is probably Intel's TXT, it's not something QM has (solely) developed internally and an underlying issue with TZ can affect many more SOC's than just QM's (since AMD also uses TrustZone[1] this could potentially also affect desktop/server CPU's). My personal bet would be that this is an issue with Keymaster, or the TZ Kernel that QM has built not with TZ itself on a hardware or even microcode level and most likely very possible to be patched. [0]http://bits-please.blogspot.co.uk/2015/08/exploring-qualcomms-trustzone.html http://bits-please.blogspot.co.uk/2015/08/exploring-qualcomm... [1]http://www.amd.com/en-us/innovations/software-technologies/security http://www.amd.com/en-us/innovations/software-technologies/s...
- happycube 10y agoWhen someone asks if you're a (security) god, say NO! (... unless you are one)
- slimsag 10y agoWhat would the implications of this be? Does it just mean that people can root all devices using this chipset? Or something worse? (sorry if this is obvious, I'm just not in the know)
- HappyTypist 10y agoThis breaks the security model of all affected devices using this chip. Including all iPhones sold today. Bye bye secure enclave. Bye bye full disk encryption.
- dogma1138 10y agoNo it doesn't, the secure enclave is a separate chip, it doesn't uses ARM trustzone, infact AFAIK Apple never implemented trustzone in any of their SOC's. Considering the previous publications by this author the issue is most likely within the TZ Kernel that QM uses not in the hardware itself, previous vulnerabilities that were disclosed by the same guy/gal/singular or plural sentient entity were patched.
- tlrobinson 10y agoTo be clear, Secure Enclave is a coprocessor on Apple's A7 and later SoCs, it's not a physically separate chip from the main processor. But you are correct it's different from TrustZone.
- dogma1138 10y agoThanks for the correction, I've read that it was a separate die but you are correct it's in the same package.
- cnvogel 10y agoJust picking some nits..., but being on a separate die still can mean that it's in the same package. https://www.google.de/search?q=multi+chip+package&tbm=isch https://www.google.de/search?q=multi+chip+package&tbm=isch
- mindcreek 10y agoSo now we know how the fbi got into the shooters phone :)
- NEDM64 10y agoIt was an iPhone. Not Qualcomm.
- mindcreek 10y agoMaybe read a little bit before down voting ? Quallcom is a chipset manufacturer Iphone is a device, has it occured to you that iphone might have quallcom tech in it ?
- abritishguy 10y agoMaybe you should read? The secure enclave is completely separate to TrustZone on an iPhone and has nothing to do with Qualcomm.
- mindcreek 10y ago"Inside, the 5c packs the same Apple A6 processor featured in the iPhone 5, a Qualcomm MDM9615M LTE modem, and a Qualcomm WTR1605L LTE/HSPA+/CDMA2K/TDSCDMA/EDGE/GPS transceiver. The back of the logic board features assorted power management, flash, and controller components from Toshiba, Qualcomm, and Broadcom, as well as a Murata Wi-Fi module. " Iphone 5c has qualcomm stuff in it.
- cloudjacker 10y agoyou dont post about this on twitter you wait
- robot 10y agoTrustzone runs an RTOS-like kernel, he likely hacked Qualcomm's implementation of this kernel to gain access. In particular this line in the screenshot hints at what he did: "Overwriting syscall_table_5 pointer" The issue is likely applicable on particular qualcomm devices, and a software patch should be possible.
- robot 10y agoTrustzone adds an additional protected mode to the cpu. IMO it complicates the CPU and adds no additional security - it's not like other protected modes in the cpu are less secure, or more hackable.
- mike_hearn 10y agoThe assumption is that yes, other modes are more hackable because they're running much larger kernels. The code inside TrustZone is supposed to be much smaller, more focused and thus more easily auditable. Unfortunately the constant stream of hacks of TrustZone applets that amount to "I smashed a buffer on the stack and got access" make me think that too often people forget the "more auditable" part.
- kuschku 10y agoAnd then you have on x86 the Intel Management Engine, running a whole graphics, audio and network stack, and a full JVM, and you notice that the promise of "more auditable" was just a smokescreen, and it really is just about DRM and backdoors.
- mrweasel 10y agoSee, this is why Twitter is a terrible news medium. TrustZone is the company I buy SSL certificates from, so what do you think people like me assume has happened? A little context wouldn't have hurt anyone.
- zimmerfrei 10y agoGranted that details are not there yet (but from previous work done by the author one can guess), would a formally proven OS like seL4 have prevented this? seL4 is somewhat weak on HW support but the functionality required in the secure domain doesn't do much I/O anyway.
- laginimaineb 10y agoFWIW, formal verification requires a complete and exact spec - the TZ kernel is very complex and interacts with nearly all the peripherals on the SoC, it doesn't just manage QSEE applications. I think creating a spec for something like that would be really hard.
- Eridrus 10y agoThe whole point of using seL4 is that you can use it to provide guaranteed isolation. If you were to use seL4 it would be so that you could write those drivers in user mode and so that a bug in one would not let you extract crypto keys in another.