3 ms·
I hope there is a way to patch this remotely. TrustZone is on quite a few devices today.[1] If it's not, well, uhh, yeah this is kind of a problem. 1. http://
by guimarin 10y ago
I hope there is a way to patch this remotely. TrustZone is on quite a few devices today.[1]
If it's not, well, uhh, yeah this is kind of a problem.
1. http://www.arm.com/products/processors/technologies/trustzone/ http://www.arm.com/products/processors/technologies/trustzon...
- dogma1138 10y agoKeymaster is a Key Management application that runs "ontop" of TrustZone this doesn't mean that TrustZone or even QM's (hardware) implementation of TrustZone is flawed. It's more likely than not just a flaw within Keymaster itself, or within the Trustzone Kernel which means that this can effectively be patched, this isn't the first time vulnerabilities like this have been identified[0] (same author) and previous issues have been patched. For anyone who wonders TrustZone is a Trusted Execution Environment (TEE) technology for ARM CPU's the more known equivalent is probably Intel's TXT, it's not something QM has (solely) developed internally and an underlying issue with TZ can affect many more SOC's than just QM's (since AMD also uses TrustZone[1] this could potentially also affect desktop/server CPU's). My personal bet would be that this is an issue with Keymaster, or the TZ Kernel that QM has built not with TZ itself on a hardware or even microcode level and most likely very possible to be patched. [0]http://bits-please.blogspot.co.uk/2015/08/exploring-qualcomms-trustzone.html http://bits-please.blogspot.co.uk/2015/08/exploring-qualcomm... [1]http://www.amd.com/en-us/innovations/software-technologies/security http://www.amd.com/en-us/innovations/software-technologies/s...