4 ms·
Trustzone adds an additional protected mode to the cpu. IMO it complicates the CPU and adds no additional security - it's not like other protected modes in the
by robot 10y ago
Trustzone adds an additional protected mode to the cpu. IMO it complicates the CPU and adds no additional security - it's not like other protected modes in the cpu are less secure, or more hackable.
- mike_hearn 10y agoThe assumption is that yes, other modes are more hackable because they're running much larger kernels. The code inside TrustZone is supposed to be much smaller, more focused and thus more easily auditable. Unfortunately the constant stream of hacks of TrustZone applets that amount to "I smashed a buffer on the stack and got access" make me think that too often people forget the "more auditable" part.
- kuschku 10y agoAnd then you have on x86 the Intel Management Engine, running a whole graphics, audio and network stack, and a full JVM, and you notice that the promise of "more auditable" was just a smokescreen, and it really is just about DRM and backdoors.