Live data from Hacker News

Serious flaws in the way Samsung phones encrypt key material in TrustZone

twitter.com

21–30 of 91 posts

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#21
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

I'd argue that most Asian companies don't. China has really stepped up their game there I would say. From what I heard a decade or so ago, they used to hire a lot of software people from the valley to get some of the culture established in their organizations for a short period of time.

To some extent I'd say User Experience is directly correlated with how valuable software engineers are in that particular society.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#22
post #7
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

It gives me the impression that, even though I paid good money on it, Samsung doesn't see me as owner and will leech as much private data off me as they possibly can.

I have never had any other impression of any smartphone.

Probably why I don't carry one.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#23
post #6

I personally don't like how it's possible to store data on my device without me being able to access the data. Also most of the time these keys are used for DRM. So... good IMO.

I have some bad news for you: that's possible with just about every computer introduced since 2013.

Google "Intel Management Engine" or "AMD PSP" or "ARM TrustZone".

The last of these could, in theory, be less bad, except no ARM licensee except Rockchip (and maybe Apple -- jury is still out there) has chosen the "be less bad" option.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#24
post #13

Earlier quoted context omitted.

> before going to Google Pixels Which isn't any better IMO. Most recent Pixels have been a buggy mess from launch. Google doesn't see to give a damn about the quality of their devices which is especially bad considering they come at flagship prices. On the other side, my mom's cheap Samsung A52 has been great so far.

My experience is that Pixel devices are far and away more competent than Samsung in many regards, but with the caveat that Samsung devices ship in a finished, stable state, but Pixel devices ship as if they’re not quite finished. The software is usually OK, but the hardware tends to be lacking in many regards. This is terrible since hardware can’t really be fixed later down the road, at BEST software workarounds can…

Pixel 1 and 2 were made by HTC. Pixel 2 XL however was manufactured by LG.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#26
post #14

Earlier quoted context omitted.

True, Samsung makes a big deal of it. But they don’t actually deserve that title imo. They’re hardly a worthy contender. I am not an apple fan boy, but Samsung is just nowhere close to the apple experience.

Well, I own a few Samsung devices. There is no Samsung experience. I don't bother signing in into a Samsung account or using their store. What for? I already have to be signed in into Google's store to get updates for the apps I must use. Samsung's one is useless and it's not the reason I bought from them. I bought an A40 because it was the smallest Android phone on the market (and yet almost one inch too tall) and a…

Until recent Samsung smart devices, you HAD to use their store and the experience was horrendous. Full of nonworking paid apps, no working review system that I could see, it was an absolute nightmare to use. It's actually quite sad cause the hardware itself wasn't bad and the battery life of Tizen was fantastic.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#27
post #6

I personally don't like how it's possible to store data on my device without me being able to access the data. Also most of the time these keys are used for DRM. So... good IMO.

I have some bad news for you: that's possible with just about every computer introduced since 2013. Google "Intel Management Engine" or "AMD PSP" or "ARM TrustZone". The last of these could, in theory, be less bad, except no ARM licensee except Rockchip (and maybe Apple -- jury is still out there) has chosen the "be less bad" option.

I'd say this is more in-line with Intel SGX than Intel ME.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#28
post #20

Earlier quoted context omitted.

LG does the same. I bought good OLED and still, I had to connect pihole to block ads... New LG's are even worse. I don't know what I do if my current TV will stop working. I want only display, I don't want any additional features (ads, personalization etc.).

I have two new LG TVs, never connected them to the internet. I do all my media consumption via a ATV and rpi

My new Sony TV wouldn't allow me to do anything without connecting it to the internet during initial setup. I just wanted to use it as a dumb screen to show HDMI signal. But even that wouldn't work without initially connecting it to the internet. I haven't connected it to the internet since and so far it hasn't stopped working, but I wouldn't be too surprised if it does as some point and forces me to reconnect and update it.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#29
post #15

Earlier quoted context omitted.

Exactly my first thoughts. Key is derived from "user-controlled data". That makes sense, it's my phone, isn't it? Why would the phone need to encrypt data in a way that the user can't access it.

The user positive use is securely booting to a password prompt to decrypt your data. Without this security working, anyone who steals your phone will be able to get all the data you have saved on it.

That's kind of the thing with Microsoft's bitlocker as well. It automatically decrypts the hard drive on boot, so the only thing it could protect you from is someone removing the hard drive and mounting it somewhere else. But if they have physical access to the device, why would they do that?

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#30
post #14

Earlier quoted context omitted.

True, Samsung makes a big deal of it. But they don’t actually deserve that title imo. They’re hardly a worthy contender. I am not an apple fan boy, but Samsung is just nowhere close to the apple experience.

Well, I own a few Samsung devices. There is no Samsung experience. I don't bother signing in into a Samsung account or using their store. What for? I already have to be signed in into Google's store to get updates for the apps I must use. Samsung's one is useless and it's not the reason I bought from them. I bought an A40 because it was the smallest Android phone on the market (and yet almost one inch too tall) and a…

I really do hate how big phones have gotten now. If it wasn't for f-droid I would just get an iphone, at least they make phones in sane sizes
Post reply on HN