3 ms·
I don’t have deep knowledge of the security architecture here but, in general the key doesn’t need to be compromised to retrieve data in secure systems. What p
by btbuilder 7y ago
I don’t have deep knowledge of the security architecture here but, in general the key doesn’t need to be compromised to retrieve data in secure systems.
What prevents unauthorized firmware from requesting that the Secure Enclave decrypt all data? Similar to having control over an HSM - you can’t extract the key but you can perform cryptographic operations.
- mschuster91 7y agoThe SE will still require a password or other authentication data (e.g. iris/finger print, biometric measurements) until it will use its key to decrypt the data. The only ways around this are: * physical extraction of the embedded memory in the SE (I'm not sure if this is actually feasible, it's certainly a destructive attack) * "updating" the SE firmware - this is what the FBI wanted Apple to do in that terrorism case, that Apple develop a SE firmware that leaks the secret key * exploiting bugs in the SE firmware - this is what the FBI ended up doing by hiring either Cellebrite or some anonymous hackers (depending on which source one believes).
- btbuilder 7y agoI see. Hence evil maid attack. If someone has temporary physical access they could install malware that captures data when the device is unlocked. Chargers as an attack vector seem more likely, if more mundane.
- als0 7y agoIn the case of malicious chargers I believe Apple already authenticates peripherals to make data capture more difficult. If you’re unauthenticated then you will not be able to do much unless explicitly authorised. Of course, none of that matters if you can reflash the device or exploit the boot ROM.
- tgragnato 7y ago> exploiting bugs in the SE firmware / "updating" the SE firmware why not both?