Apple’s Secure Enclave Processor (SEP) Firmware Decrypted
hackaday.com
hackaday.com
Also, don't be mislead by the headline. To quote a comment on the article:
"Imagine the Secure Enclave as a vault. Apple hung a big, dark curtain over it to prevent anyone from even seeing the vault. Now, that curtain has been opened and people can see the vault. The vault, however, is still locked as securely as ever."
For more on that, as mentioned in the linked page, there’s the “Demystifying the Secure Enclave Processor” talk from Blackhat:
https://www.youtube.com/watch?v=7UNeUT_sRos
Or here’s the PDF:
https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-De...
So basically it’s only misleading to 99.9999% of people?
I think that 99.99% applies to even HN and it certainly applies to me.
And even that's a tall order.
Nope. Apple published a whitepaper that details how the SEP works.[1] Decrypting the firmware does help researchers look for vulnerabilities in the implementation, but it's not like Apple is relying on it being a black box.
[1] https://www.apple.com/business/docs/iOS_Security_Guide.pdf
If you would like to avoid such replies in the future, try to avoid making strong, absolute statements. When I talk about topics I am unfamiliar with, I tend to use phrases like "I think" and "I believe" quite sparingly.
> Says the PhD candidate in hardware security.
Again, the fact of the matter is that the Apple security whitepaper is a marketing document. I'm not sure what my background has to do with that though.
From the [ios security guide]:
> The Secure Enclave provides all cryptographic operations for Data Protection key management and maintains the integrity of Data Protection even if the kernel has been compromised.
e.g. you can encrypt and decrypt, referencing a key by id, but without having the private key ever leave the enclave, even if the app or iOS kernel gets compromised.
[ios security guide] https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The Secure Enclave section is pretty short and the entire document is very approachable.
Several months ago I saw a project making wallet software that used the enclave. I forget who they were but I think they'll have a hard sell; everyone just reflexively assumed it was insecure because it was on a phone.
It's unfortunate people would draw negative connotations from it being on a mobile device. The security architecture of iOS and the SEP combined with the relatively wide deployment of iPhones makes for a great number of use cases.
Both of these modules use the secp256r1 curve at least, so the signature verification algo which runs on the blockchain can be the same for both types of devices. (You can find some more details on this topic here: http://blog.enuma.io/update/2016/11/01/a-tale-of-two-curves-...)
Since the Byzantium fork there are some precompiles available for curve operations. Using those for the r1 curve signature verification in EVM code brought down the gas cost to practical levels.
Ultimately there will be some exposure from this, and they'll address each exploit as it comes just like the rest of the system.