3 ms·
This is not simply about the presence of a "secure enclave" or security module as Google calls it. It's about preventing the firmware on the security module fro
by bitmapbrother 8y ago
This is not simply about the presence of a "secure enclave" or security module as Google calls it. It's about preventing the firmware on the security module from being compromised without knowing the users password.
To mitigate these risks, Google Pixel 2 devices implement insider attack resistance in the tamper-resistant hardware security module that guards the encryption keys for user data. This helps prevent an attacker who manages to produce properly signed malicious firmware from installing it on the security module in a lost or stolen device without the user's cooperation. Specifically, it is not possible to upgrade the firmware that checks the user's password unless you present the correct user password. There is a way to "force" an upgrade, for example when a returned device is refurbished for resale, but forcing it wipes the secrets used to decrypt the user's data, effectively destroying it.
- jakobegger 8y agoYes, I know. I thought that the secure enclave requires the user passcode to authorize an update, but after re-reading the iOS security whitepaper, I am no longer sure that this is actually correct. (it’s not mentioned anywhere) So while you do have to provide your passcode to update an iOS device, it could be that this requirement is only enforced at a higher level (ie. not by the secure enclave itself).