4 ms·
Not that that's perfectly secure
by timdiggerm 11y ago
Not that that's perfectly secure
- cwyers 11y agoYeah, it's only as secure as Tesla's ability to secure its private key.
- mikeash 11y agoAnd their ability to verify the signature on the car. Even if the private key is totally secure, you could either find a weakness in the signature verification, or find an exploit that lets you bypass it entirely.
- UnoriginalGuy 11y agoThat's an extremely rare vector for exploitation. I can think of one specific case where a vendor completely forgot to check the result of a signature check, but aside from that signature checking is well understood and rarely goes wrong. But to be honest people are taking their specification and dooms-day-ism to stupid extremes. Soon we'll be talking about "it is only as secure as the CPU, what if you find a CPU bug and bypass all security?!"
- ZoFreX 11y ago> signature checking is well understood and rarely goes wrong I would argue otherwise, plenty of signature schemes give you enough rope to hang yourself. The Playstation 3 example springs to mind!
- pigeons 11y agoSignature verification for android applications has been a tough one: http://www.saurik.com/id/19 http://www.saurik.com/id/19
- takeda 11y agoThere's plenty room for bugs in mechanism like that. For example Motorola Droid (back in 2010) was locked and only accepted signed updates. There was a bug where you could bypass it by using authentic update and appending your payload at the end of that file.
- thesteamboat 11y agoInteresting, can you point me to a news article or link? Shouldn't that have been rejected as an improperly signed file as (update+payload) should have a different signature than (update)? I'm want to know whether I'm misinterpreting something, misunderstanding something, or the signatures were misimplemented.
- kuschku 11y agoOnly the header was signed – that was the issue. It was made to save computational power on the device.
- takeda 11y agoThe original forum where it was posted doesn't exist anymore and there doesn't seem to be archived copy. Here's another page which is describing the steps: http://www.areacellphone.com/2009/12/motorola-droid-rooted-howto-root-droid/ http://www.areacellphone.com/2009/12/motorola-droid-rooted-h... Here is the commit with a bug fix: http://review.source.android.com/12807 http://review.source.android.com/12807 and actual diff: https://android-review.googlesource.com/#/c/12807/1/verifier.c https://android-review.googlesource.com/#/c/12807/1/verifier...