TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Serious flaws in the way Samsung phones encrypt key material in TrustZone

185 pointsby caaqilabout 3 years ago

11 comments

qiqitoriabout 3 years ago
I personally don't like how it's possible to store data on my device without me being able to access the data. Also most of the time these keys are used for DRM. So... good IMO.
评论 #30514289 未加载
评论 #30512104 未加载
评论 #30510816 未加载
评论 #30510307 未加载
评论 #30511827 未加载
SiebenHeavenabout 3 years ago
I am pretty surprised how they allowed reusing IV. Unique IV is explicitly mentioned to be an assumption for AES GCM (first sentence in security section of AES-GCM wikipedia page)<p>How could anyone design TA (i.e application whose whole point is security and hence it runs in the secure mode) and allow user to set IV in the API?
评论 #30513472 未加载
评论 #30514894 未加载
jsmith99about 3 years ago
This was patched a few months ago <a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;2022&#x2F;02&#x2F;23&#x2F;samsung_encryption_phones&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.theregister.com&#x2F;2022&#x2F;02&#x2F;23&#x2F;samsung_encryption_ph...</a> (right at bottom of article)
4pkjaiabout 3 years ago
I used a Samsung phone for a few months, it gave me the strong impression that they really don&#x27;t know how to develop software properly.
评论 #30510248 未加载
评论 #30514210 未加载
评论 #30510674 未加载
评论 #30511020 未加载
评论 #30510271 未加载
评论 #30510567 未加载
评论 #30510783 未加载
评论 #30510374 未加载
评论 #30510207 未加载
评论 #30514966 未加载
评论 #30510820 未加载
评论 #30510220 未加载
评论 #30514530 未加载
评论 #30511836 未加载
compsciphdabout 3 years ago
I&#x27;m wondering if this is related to how people have extracted widevine layer 1 keys?
xxporabout 3 years ago
Having used a lot of Samsung software, I have to wonder if the root cause here is a language barrier. Their software frequently has translation errors, and their kernels are compiled on a computer in Korean Standard Time. For a lot of open source software, or basic introductions into, say, how to use AES-GCM, they&#x27;re really only available in English reliably. Content in other languages frequently lags or is non existent.<p>I could totally imagine something like Google Translate missing a critical not or similar that completely changes the meaning of a sentence. For technical documentation, that could be a huge problem.
3npabout 3 years ago
I have an old Samsung Galaxy S7 that I bricked a year back in the process of trying to make a backup of the data on it (the irony)... I think I may have blown the knox fuse. Could this be leveraged to give me my files back?
llui85about 3 years ago
<a href="https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1495935700545454084.html" rel="nofollow">https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1495935700545454084.html</a>
getcrunkabout 3 years ago
A while wasn&#x27;t there something about their ssd&#x27;s encryption (maybe with windows and bitlocker)
dbrgnabout 3 years ago
Don&#x27;t buy phones from Samsung. They&#x27;re the worst. They&#x27;ve been #1 on <a href="https:&#x2F;&#x2F;dontkillmyapp.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;dontkillmyapp.com&#x2F;</a> for a while now.
评论 #30514768 未加载
评论 #30514826 未加载
评论 #30514935 未加载
jnsactabout 3 years ago
i have a samsung phone for about two years now. it reinds me to update the system all the time, almost every month. i dont do the update now. i just ignore it, i dont need fancy new features. i love it not being that smart. i love it the old way.
评论 #30512170 未加载
评论 #30511825 未加载