3 ms·
Secure enclaves and their ilk should really not be soldered on devices, or on silicon. What happens if/when someone manages to create a persistent enclave expl
by lostmyoldone 6y ago
Secure enclaves and their ilk should really not be soldered on devices, or on silicon.
What happens if/when someone manages to create a persistent enclave exploit?
It might be entirely impossible to know if you're affected, and the only plausible (but not very reasonable) end user mitigation might be to replace an entire logic board.
Likely for a quite hefty sum of money.
I'm not saying it's all together a bad idea with a more secure processing unit, but there are quite literally no good (user centric) reason to make it hard to replace, certainly not in anything bigger than a phone form factor.
Specifically about Apple:
With its persistent claims of user centricity should not need to be told this, that it should be removable/movable, unless of course this has nothing to do with the user at all. Exactly what is up for debate, but there's a certain asymmetry in the message, the effort required, the end user benefits, and the trajectory of this work that I have a hard time reconciling with anything primarily benefitting the user. Especially considering the otherwise quite lackluster attention to quality and security seen in the last few years. Lots of security features that are ostensibly for the benefit of the user, but where one can tell a parallel story that is about complete platform control, in the light of which the design decisions seems to make more sense.
- znpy 6y agoThe same could be said for storage and ram chips. But apple really wants you to buy a new device as often as your paycheck allows you, so this kind of things (removable secure enclave) isn't going to happen, most likely.
- Tagbert 6y agoApple actually goes out of it’s way to maintain compatibility with older devices much longer than most manufacturers. Even the ones that no longer get the most recent OS get security patches for some time after. Yes, it would be nice to have replaceable RAM and SSD in phones, but that would not benefit most users who would never replace anything. Making those things replaceable means they are bulkier and more complex to manufacture reliably. Apple seems to have made a trade-off there.
- kalleboo 6y agoThe SIM card is really the original secure enclave, and even has protected storage of contacts and messages, and early mobile payment solutions in Asia and Europe used the SIM card to securely store payment secrets. Unfortunately, mobile operators have been pretty terrible at keeping up with security (neglecting to block old and broken voice crypto etc)