Attacking Titan M with Only One Byte
blog.quarkslab.com
Attacking Titan M with Only One Byte
1–10 of 84 posts
Re: Attacking Titan M with Only One Byte
#2Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD.
If fully compromising Google's own security chip to dump all private keys isn't worth the full $1 Million bounty, I honestly don't know what is.
Really, what would, in the mind of those on the internal committee, constitute justification for the $1 Million bounty?
Re: Attacking Titan M with Only One Byte
#3Re: Attacking Titan M with Only One Byte
#4> Then, we need a way to access the key blobs on the Android file system, which can be done again by being root, or with some exploit to bypass File Based Encryption or the uid access control.
Re: Attacking Titan M with Only One Byte
#5For a moment I thought this is something related to the anime
Re: Attacking Titan M with Only One Byte
#6Don't lose sight of the fact that the purpose of this and other TPM-like devices is to hide secrets from its owner.
Re: Attacking Titan M with Only One Byte
#7For a moment I thought this is something related to the anime
Myself pulled in hoping for a historical tale of attacking vulnerabilities in Titan ICBMs.
edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons:
1. Discussing "nukes" openly where I come from would raise some eyebrows.
2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.Re: Attacking Titan M with Only One Byte
#8This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…
Re: Attacking Titan M with Only One Byte
#9Earlier quoted context omitted.
Myself pulled in hoping for a historical tale of attacking vulnerabilities in Titan ICBMs.
Just curious - if the usage of acronym here a soft-euphemism? (So that only those who knew or care to know gets it) edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons: 1. Discussing "nukes" openly where I come from would raise some eyebrows. 2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.
Re: Attacking Titan M with Only One Byte
#10I thought I read the whole thing. Did I miss that explanation?