4 ms·
"Crack the hash"? Does this mean you were employing some novel hashing algorithm and relying on its secrecy? If so your employer were never serious about securi
by EPWN3D 4mo ago
"Crack the hash"? Does this mean you were employing some novel hashing algorithm and relying on its secrecy? If so your employer were never serious about security in the first place. Hardware attestation is more or less a solved problem, and that solution does not involve secret algorithms.
- ChrisMarshallNY 4mo agoEh. It was some kind of hash of the image. I was not involved in that project, so can't tell you exactly how it worked, but the images were "signed," and someone figured out how to "re-sign" an altered image. I think it was a fairly well-known technique.
- XorNot 4mo agoWhich still sounds like your employer was simply incompetent because why was any type of perceptual hashing scheme even involved? Signing digital data with hardware secure tokens is a commodity capability in the iPhone many of HNs users are reading this site with.
- dzhiurgis 4mo agoI think this has been around for not so long https://en.wikipedia.org/wiki/Content_Authenticity_Initiative https://en.wikipedia.org/wiki/Content_Authenticity_Initiativ...
- XorNot 4mo agoSure but conceptually no one should've been able to crack any hashing scheme anyone half-way decent at their job could come up. SHA256 is the default and it's unbroken. Even SHA1 has scant few known collisions. So like...what the heck were they hashing and how that anyone was able to crack it?
- phreeza 4mo agoMaybe its more like the hash was a well known secure hash but someone managed to extract the salt/private key/signing certificate from the camera?
- SAI_Peregrinus 4mo agoMost likely is either extracting the private key from the camera or getting the camera to sign arbitrary data. If the signing isn't part of the sensor die itself there's a bus where the image data gets transferred from sensor to signer, so an attacker can inject arbitrary data onto that bus to get it signed, even though they never actually extract the signing key.
- ChrisMarshallNY 4mo agoThis was quite a while, before that.
- ChrisMarshallNY 4mo ago> your employer was simply incompetent You’re probably right. This is easy, basic stuff that any recent college grad can do with their eyes closed.