5 ms·
I am confused by the threat model here. It seems that we want to assure (among others) confidentiality of the data the user is inputting. However, I don't think
by robryk 7y ago
I am confused by the threat model here. It seems that we want to assure (among others) confidentiality of the data the user is inputting. However, I don't think any of the planned data input channels would be hard to eavesdrop on from the POV of the user's phone:
a) input via hardware keyboard, if the betrusted is a part of the phone case, should be simple to eavesdrop on based on microphone and/or accelerometer readings in the phone: different keys on the keyboard will likely be different enough.
b) input via voice can be eavesdropped on by the phone' microphone.
Do I misunderstand the guarantees betrusted intends to provide or something else?
- gchamonlive 7y agoGuarantees are, if in a controlled environment, user won't be eavesdropped by means of software intervention. That is what I got from the project
- Iv 7y agohttps://www.youtube.com/watch?v=Hzb37RyagCQ https://www.youtube.com/watch?v=Hzb37RyagCQ He starts talking about betrusted at 30:00