Live data from Hacker News

Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

bits-please.blogspot.com

1–10 of 99 posts

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#2
Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#5
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

The (thinly sourced) rumor is that Google wants to build a new phone from scratch, a separate project from Nexus

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#6
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

Are you guaranteeing that Nexus phones exist, or that Google will introduce a second line of phones?

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#7
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

This vulnerability does not make FDE pointless per se. It means that your security depends completely on the complexity of your passphrase (like the iPhone prior to the introduction of Secure Enclave). Which is still fairly bad given the typical passcode complexity on phones.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#8
post #3

Would love to see the same analysis on Samsung hardware

I'll definitely try and get around to it sometime soon. However, I wouldn't be surprised if the situation is the same... After all, the KeyMaster module was initially only meant to keep encryption keys on the device, not to safeguard FDE.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#9
post #5
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

The (thinly sourced) rumor is that Google wants to build a new phone from scratch, a separate project from Nexus

ARA?
Post reply on HN