3 ms·
If you wanted DRM keys, couldn't you just patch memfd_secret() to remove its security features, let the program use it, then have a look at the assigned memory?
by sleavey 5y ago
If you wanted DRM keys, couldn't you just patch memfd_secret() to remove its security features, let the program use it, then have a look at the assigned memory?
- c0l0 5y agoSure, on paper, that will always be possible - just not in the age of signed kernel images that are cryptographically verified by your immutable bootloader.
- deleted 5y ago[deleted]
- remram 5y agoDo we live in that age? Are there any computers that can't be made to boot an unsigned image? My experience is that Secure Boot is optional.
- MonadIsPronad 5y agoWin11 requiring TPM2.0 feels like it's edging ever closer to such an age... Can the latest iPhones boot unsigned OSs yet? I'm guessing the jailbreakers aren't _that_ fast.
- kevincox 5y agoYou can't score full marks on Android SafetyNet if you aren't using an unmodified stock ROM. https://developer.android.com/training/safetynet/attestation https://developer.android.com/training/safetynet/attestation So yes, some apps will refuse to run and in theory some services could refuse to accept requests from devices that aren't running unmodified images. I can definitely imagine something like Snapchat using this as they have actually been fairly aggressive at trying to prevent "unauthorized clients" that can save images without notification to the user.
- cmurf 5y agoWindows Hardware Compatibility Program Specification mandates that Secure Boot can be disabled and customized, by a physically present user, on non-ARM platforms, in early versions of the Windows 10 spec. Disabling Secure Boot must not be possible on ARM systems. - WHCP-Systems-Specification-1511.pdf However, looking at the -2004 spec, both customization and enable/disable sections are prefaced with (Optional for systems intended to be locked down) so it is no longer mandatory, even on x86_64 systems, to provide a physically present user with the ability to disable or customize UEFI Secure Boot. The same language is used in the -21H2 spec for Windows 11. https://docs.microsoft.com/en-us/windows-hardware/design/compatibility/whcp-specifications-policies https://docs.microsoft.com/en-us/windows-hardware/design/com...