Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
laginimaineb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
laginimaineb
4mo ago
(I work at doubleAI.) The benchmark numbers (90% wins, 2.24x speedup on average, with key attention workloads accelerated ~15x) are one part of the story. The other: AI-generated kernels can pass simple verifiers with room to spare and stil
2.
▲
WarpSpeed Approaches Speed of Light on Blackwell
(doubleai.com)
7 points
by
laginimaineb
4mo ago
|
1 comments
3.
▲
WarpSpeed automatically rewrites Nvidia core library, achieves 3.6-100x speedup
(doubleai.com)
9 points
by
laginimaineb
7mo ago
|
0 comments
4.
▲
by
laginimaineb
10y ago
Actually, I would imagine they are nothing like one another. However, Exynos uses a TrustZone TEE implementation to implement the KeyMaster module, just like Qualcomm's Snapdragon. This means that unless that TEE implementation uses a
5.
▲
by
laginimaineb
10y ago
You're right. Let's take a second to go over the issues: 1. The arbitrary code-execution in TZ has already been privately disclosed and fixed. 2. As for the second issue - I would argue that it's not an issue at all. TZ shoul
6.
▲
by
laginimaineb
10y ago
I believe so.
7.
▲
by
laginimaineb
10y ago
I'll definitely try and get around to it sometime soon. However, I wouldn't be surprised if the situation is the same... After all, the KeyMaster module was initially only meant to keep encryption keys on the device, not to safegu
8.
▲
Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption
(bits-please.blogspot.com)
341 points
by
laginimaineb
10y ago
|
98 comments
9.
▲
Hijacking Qualcomm's TrustZone Kernel
(bits-please.blogspot.com)
2 points
by
laginimaineb
10y ago
|
0 comments
10.
▲
by
laginimaineb
10y ago
FWIW, formal verification requires a complete and exact spec - the TZ kernel is very complex and interacts with nearly all the peripherals on the SoC, it doesn't just manage QSEE applications. I think creating a spec for something li
11.
▲
War of the Worlds – Hijacking the Linux Kernel from QSEE
(bits-please.blogspot.com)
2 points
by
laginimaineb
10y ago
|
0 comments
12.
▲
by
laginimaineb
10y ago
Widevine DRM is integrated into virtually all Android phones. If you're building your own ROM, you could remove the widevine.bXX files from the ROM image itself - I've never tested it, but it could probably soft-fail. There's
13.
▲
QSEE privilege escalation vulnerability and exploit
(bits-please.blogspot.com)
22 points
by
laginimaineb
10y ago
|
3 comments
14.
▲
Exploring Qualcomm's Secure Execution Environment
(bits-please.blogspot.com)
3 points
by
laginimaineb
10y ago
|
0 comments
15.
▲
by
laginimaineb
11y ago
I believe so
16.
▲
by
laginimaineb
11y ago
Don't think I'll collect it, but I will release all the details so people can do it themselves.
17.
▲
by
laginimaineb
11y ago
It will work on the Turbo! :) But you'll either need a version old enough to be vulnerable to this TrustZone exploit, or you can wait a couple of weeks until I release a new exploit (which also works on the Turbo).
18.
▲
by
laginimaineb
11y ago
Thanks! I'm also on twitter in case that helps (@laginimaineb). As for Sunshine - I'm publishing a new (even broader) zero-to-TZ saga, complete with exploits, but I'm not going to create a product out of it. So ultimately, as
19.
▲
by
laginimaineb
11y ago
AFAIK it's unknown - there's a controller on the SoC which is responsible for reading/writing the fuses, but its firmware is in mask ROM and isn't available. Perhaps it's a real chemical reaction? Maybe it's ju
20.
▲
Unlocking the Motorola Bootloader with a TrustZone Exploit
(bits-please.blogspot.com)
74 points
by
laginimaineb
11y ago
|
28 comments
21.
▲
by
laginimaineb
11y ago
In this case, it seems so. However, I must say I've reported many vulnerabilities to Google since and they've all been handled within that time-frame.
22.
▲
by
laginimaineb
11y ago
That's a great question! I didn't cover this in the blog post, but there is a primitive identical to the increment-by-one presented there, which allows me to decrement-by-one as well (I've gone into more detail in the exploit
23.
▲
by
laginimaineb
11y ago
Thank you. Also, the map is mostly Thorin's, with only slight adaptations :)
24.
▲
Android mediaserver exploit – heap thermal vision
(bits-please.blogspot.com)
38 points
by
laginimaineb
11y ago
|
7 comments
25.
▲
Android linux kernel privilege escalation (CVE-2014-4323)
(bits-please.blogspot.com)
2 points
by
laginimaineb
11y ago
|
0 comments
26.
▲
Effectively bypassing kptr_restrict on Android
(bits-please.blogspot.com)
2 points
by
laginimaineb
11y ago
|
0 comments
27.
▲
Android kernel vulnerability and exploit with full source code
(bits-please.blogspot.com)
6 points
by
laginimaineb
11y ago
|
0 comments
28.
▲
by
laginimaineb
11y ago
Thanks! More to follow soon :)
29.
▲
by
laginimaineb
11y ago
Sure, see the first part of the blog post, under "Responsible Disclosure"
30.
▲
by
laginimaineb
11y ago
(Disclaimer: I'm the author of this blog) In this post I cover the development of a full TrustZone exploit in MSM8974 (Snapdragon 800) SoCs, resulting in arbitrary code execution in the "Secure World". I've also provided
More ›