Live data from Hacker News

Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

bits-please.blogspot.com

21–30 of 99 posts

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#21
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

> Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless.

For 99% of the users, this is complete nonsense. Why do we encrypt the phone? Are we afraid of the NSA or whatever agency cracking our phones? No! The reason most of us encrypt the phone is to prevent others from posting our pictures or reading our mail.

When somebody else finds my phone, or steals it, the four digit PIN is enough protection. Then again, I don't use a four digit PIN, but something longer, and from six or up it's really strong enough for manual unlocking.

People who have the means to read contents from the memory chips, they probably have the means to use other measures to get what they want.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#22
post #5
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

The (thinly sourced) rumor is that Google wants to build a new phone from scratch, a separate project from Nexus

For this to work they only need one little chip that can do what the secure enclave does. They can then require that chip in Android phones. That's a lot cheaper and easier. Then they need to control the manufacturing of this chip, not outsource it to China.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#23
post #16

It doesn't really break the encryption, as long as the password is strong enough to prevent brute forcing. Relying on a weak password and a "trusted computing" mechanism like this one from Qualcomm to prevent an attacker with physical access from brute forcing it is not really advisable. Using such a mechanism at all has downsides since it means that you lose the data if the mechanism or the entire device stops worki…

But how many Android users do you know that actually have a strong password? (Speaking of which: Google's decision to not allow strong encryption passwords together with short screen unlock PINs/patterns is not helping here. It's actually possible, but they don't expose the user interface to change them separately, probably for usability reasons.)

Also, while I would agree as far as PCs are concerned, moving the eMMC to a new phone's mainboard is probably also not a likely scenario.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#24
post #13

Fascinating article, the more I learn about crypto and security the more obvious it becomes how hard this stuff is to get right.

There is no getting it "right" just less wrong; aka "perfect" security does not exist.

Isn't that still an open question?

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#25
post #6

Earlier quoted context omitted.

Are you guaranteeing that Nexus phones exist, or that Google will introduce a second line of phones?

Google don't manufacture the Nexus.

But they had a chance (and didn't) to bring that all in house with the Motorola buy, no?

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#26
post #25

Earlier quoted context omitted.

Google don't manufacture the Nexus.

But they had a chance (and didn't) to bring that all in house with the Motorola buy, no?

Google wanted and kept most of the patents.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#27
So if I understood correctly, there are 5 requirements for such a system to be secure:

  1: secure/unmodifiable cryptographic processor
  2: with unremovable rate limiting
  3: and exclusive access to a hardware key
  
  4: cryptographic processor has the only function of encrypting user data based on
  5: hardware key and a user supplied pin/key
Errors done by Qualcomm:

  Violated 3: Hardware key not exclusivly readable by cryptographic processor
  Violated 5: Encryption based on derived key
Anything I overlooked?

(edited: formatting)

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#28
post #24
post #13

Earlier quoted context omitted.

There is no getting it "right" just less wrong; aka "perfect" security does not exist.

Isn't that still an open question?

Maybe in the sense that one can ever really prove it to be "perfect".

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#29
post #2

Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. I guarantee Google really wants to build their own branded phones with their own secure Android version and gain Apple's advantages in building secure systems because you own everything.

> Since the security of Android depends on hardware and OEM software not under Google's control, depending on FDE is apparently pointless. For 99% of the users, this is complete nonsense. Why do we encrypt the phone? Are we afraid of the NSA or whatever agency cracking our phones? No! The reason most of us encrypt the phone is to prevent others from posting our pictures or reading our mail. When somebody else finds m…

There are levels of threat and protection between those you mentioned. As the threat from people with access to "other measures" increases, you moght at least want to make them work for it and have to go through proper channels.

Re: Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption

#30
post #5

Earlier quoted context omitted.

The (thinly sourced) rumor is that Google wants to build a new phone from scratch, a separate project from Nexus

For this to work they only need one little chip that can do what the secure enclave does. They can then require that chip in Android phones. That's a lot cheaper and easier. Then they need to control the manufacturing of this chip, not outsource it to China.

If only they had an OEM to do this, with a plant in Texas....
Post reply on HN