Including all iPhones sold today. Bye bye secure enclave. Bye bye full disk encryption.
Including all iPhones sold today. Bye bye secure enclave. Bye bye full disk encryption.
Considering the previous publications by this author the issue is most likely within the TZ Kernel that QM uses not in the hardware itself, previous vulnerabilities that were disclosed by the same guy/gal/singular or plural sentient entity were patched.
Even worse than their version that works with a hardware secure enclave is the version which works without one.
How does that one work? By ensuring that the user didn’t modify the OS image.
That’s literally all security there is.
It’d be a lot better if they’d just build a security model that doesn’t have to rely on the device being secure, but instead rely on the banks’ servers being secure.
I can thank some US banks that I, as German Android user, get locked down by Google. I get all the issues, none of the benefits.
One source of many: https://www.ifixit.com/Teardown/iPhone+6s+Teardown/48170