Does it just mean that people can root all devices using this chipset? Or something worse?
(sorry if this is obvious, I'm just not in the know)
Does it just mean that people can root all devices using this chipset? Or something worse?
(sorry if this is obvious, I'm just not in the know)
I'm not 100% sure if KM is only used to store "user" keys such as encryption keys for FDE or does it also has access to other keys stored on the hardware key storage such as the ones used to verify the firmware and OS images allowing you to bypass vendor restrictions that prevent running unsigned bootloaders, firmware, and OS images on the device.
That said QM's TrustZone kernel AFAIK pretty much runs as root (and somewhat even higher) so ACE vulnerabilities in it can be effectively used to execute any command with root or higher privileges regardless if you can fully "root" the phone or not.
Including all iPhones sold today. Bye bye secure enclave. Bye bye full disk encryption.
Considering the previous publications by this author the issue is most likely within the TZ Kernel that QM uses not in the hardware itself, previous vulnerabilities that were disclosed by the same guy/gal/singular or plural sentient entity were patched.
Even worse than their version that works with a hardware secure enclave is the version which works without one.
How does that one work? By ensuring that the user didn’t modify the OS image.
That’s literally all security there is.
It’d be a lot better if they’d just build a security model that doesn’t have to rely on the device being secure, but instead rely on the banks’ servers being secure.
I can thank some US banks that I, as German Android user, get locked down by Google. I get all the issues, none of the benefits.
One source of many: https://www.ifixit.com/Teardown/iPhone+6s+Teardown/48170