Live data from Hacker News

Serious flaws in the way Samsung phones encrypt key material in TrustZone

twitter.com

81–90 of 91 posts

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#81
post #58

Earlier quoted context omitted.

Physical access does not imply easy arbitrary code execution. Consoles are largely protected by the same technology, how often do you see people achieving code execution on them by tampering with the hardware?

All the time? Hardmods have been a thing since the first consoles, all the way down to the latest Nintendo Switch. Also, consoles are "protecting" not the user, but the manufacturer - which is exactly the point people are trying to make.

Haha. You’re bringing up tech from 20 years ago when we’re discussing modern security measures, aren’t you very clever.

What hardmods do you know of for current gen consoles? Even the previous generation mostly fixed all public hardware based attacks.

This is standardized hardware that would be a relatively soft target to build tooling against, yet modchips are essentially dead because the attacks are just far too difficult.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#82

Earlier quoted context omitted.

I find it hard to believe there wasn't a work around for your tv to be set up without Internet. For example the Sony web site doesn't seem to support what you are saying https://www.sony-asia.com/electronics/support/articles/00113... I set up my grandmothers sony tv last year without Internet.

I was trying to avoid it. I am tech savvy. I could not find a workaround. There was no way, at least none I could find despite my efforts, to skip the screen requiring you to connect without connecting.

That's very strange. I'm too lazy to factory reset the Sony tv I bought this year to try it, but here's a link to a "q and a" from Best Buy saying someone set up my model without Internet during a hurricane, and Sony themself indicating it works without Internet.

https://www.bestbuy.com/site/questions/sony-77-class-bravia-...

So assuming you are software savvy enough to not have missed the correct prompt, I have to assume there was a bug with the firmware version you recieved.

Some people like my 92 year old Grandmom don't have internet, and it would make no sense for Sony to have to deal with returns from them.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#83
post #14

Earlier quoted context omitted.

Well, I own a few Samsung devices. There is no Samsung experience. I don't bother signing in into a Samsung account or using their store. What for? I already have to be signed in into Google's store to get updates for the apps I must use. Samsung's one is useless and it's not the reason I bought from them. I bought an A40 because it was the smallest Android phone on the market (and yet almost one inch too tall) and a…

> and a tablet (S5e?) because it had Linux in DeX. Is that still a thing? A few years ago I was interested in that, as an alternative to a laptop, but I seem to remember that it was on the way out.

They dropped support. The update to Android 10 removes it. Probably because 16.04 is EOL and they should have paid Canonical again to make X11 and possibly other systems work on Android. The number of users of that feature was probably low.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#84
post #30
post #14

Earlier quoted context omitted.

Well, I own a few Samsung devices. There is no Samsung experience. I don't bother signing in into a Samsung account or using their store. What for? I already have to be signed in into Google's store to get updates for the apps I must use. Samsung's one is useless and it's not the reason I bought from them. I bought an A40 because it was the smallest Android phone on the market (and yet almost one inch too tall) and a…

I really do hate how big phones have gotten now. If it wasn't for f-droid I would just get an iphone, at least they make phones in sane sizes

The old SE was nice. The new SE is big. The 12 mini is a little smaller.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#85
post #81

Earlier quoted context omitted.

All the time? Hardmods have been a thing since the first consoles, all the way down to the latest Nintendo Switch. Also, consoles are "protecting" not the user, but the manufacturer - which is exactly the point people are trying to make.

Haha. You’re bringing up tech from 20 years ago when we’re discussing modern security measures, aren’t you very clever. What hardmods do you know of for current gen consoles? Even the previous generation mostly fixed all public hardware based attacks. This is standardized hardware that would be a relatively soft target to build tooling against, yet modchips are essentially dead because the attacks are just far too di…

This is pretty confusing, hardmods are definitely a thing for the current gen Switch - AFAIK it's the only way to jailbreak ones that were manufactured after some date and don't allow soft mods.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#86
Having used a lot of Samsung software, I have to wonder if the root cause here is a language barrier. Their software frequently has translation errors, and their kernels are compiled on a computer in Korean Standard Time. For a lot of open source software, or basic introductions into, say, how to use AES-GCM, they're really only available in English reliably. Content in other languages frequently lags or is non existent.

I could totally imagine something like Google Translate missing a critical not or similar that completely changes the meaning of a sentence. For technical documentation, that could be a huge problem.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#87

Earlier quoted context omitted.

I was trying to avoid it. I am tech savvy. I could not find a workaround. There was no way, at least none I could find despite my efforts, to skip the screen requiring you to connect without connecting.

That's very strange. I'm too lazy to factory reset the Sony tv I bought this year to try it, but here's a link to a "q and a" from Best Buy saying someone set up my model without Internet during a hurricane, and Sony themself indicating it works without Internet. https://www.bestbuy.com/site/questions/sony-77-class-bravia-... So assuming you are software savvy enough to not have missed the correct prompt, I have to a…

That is strange. I have a different model (KD65X80J), but it seems to have all the same options and software. Yet, even though I chose Basic TV instead of Android TV, the internet connection page did not have the option to skip. It might be a bug, as you suggest.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#88
post #85
post #81

Earlier quoted context omitted.

Haha. You’re bringing up tech from 20 years ago when we’re discussing modern security measures, aren’t you very clever. What hardmods do you know of for current gen consoles? Even the previous generation mostly fixed all public hardware based attacks. This is standardized hardware that would be a relatively soft target to build tooling against, yet modchips are essentially dead because the attacks are just far too di…

This is pretty confusing, hardmods are definitely a thing for the current gen Switch - AFAIK it's the only way to jailbreak ones that were manufactured after some date and don't allow soft mods.

Nintendo famously has the worst security of all the console manufacturers.

That there are still no good attacks for the xbox one speaks volumes.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#89
post #35

Earlier quoted context omitted.

On a phone it's in active use, on your x86 device it's up to you.

No, it is most definitely not up to you. That's the problem.

Depends on how paranoid you are. There's no absolute assurance that my x86 hardware and OS aren't secretly using them for some active purpose without user knowledge, but all the evidence so far points to the fact that it's not, and the reputation risks to the vendors would be large if they got caught doing this kind of underhanded thing. Whereas my phone OS core functionality relies on the functionality and I know it's being used all the time for DRM etc.

(I'm not hapy with the x86 situation either, but it's still less bad)

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#90
post #70

Don't buy phones from Samsung. They're the worst. They've been #1 on https://dontkillmyapp.com/ for a while now.

There are around 1000 other factors in buying phones, mostly much more important to most users. I get it when ie developers are frustrated by inconsistent behavior across phones, but for example I prefer longer battery life compared to something that still runs in the background because I used it few hours ago.

This is also about developer frustration, but not only. Over the years, I've used various alarm clock apps. There were some Huawei phones where it was literally impossible to get those alarm clock apps to work, because even if you added it to all whitelists, it would still kill the app in the background. Another issue is if you're using a messenger with VoIP functionality that you don't use every day. When an incoming call is received after not using the app for a while, it simply wouldn't ring.

Stock Android already contains energy saving mechanisms that work reasonably well. By piling potentially broken additional battery saving mechanisms on top of that, you risk breaking the phone for certain use cases. At the very least, as a user of that phone, there should be an easy way to exclude certain apps from energy saving measures. (Let's pick out Huawei again, where even if you added an app to such exclusion lists, after a few days the OS would randomly remove the app from that exclusion list again. Plus, there was some kind of "lock" that you could activate in the app switcher, but that lock wouldn't survive a reboot.)

Because some of the energy saving measures are so extreme, some manufacturers put popular apps on internal exclusion lists. These apps work fine, but apps by smaller developers don't. This is a major source of market distortion.

Huawei used to be the worst offender in this space, but it has gotten a little bit better by now. Nokia also had a phase where they had a horribly broken energy saver, but thankfully they got rid of that. Samsung has gotten worse and worse over the last years.

Post reply on HN