Live data from Hacker News

Attacking Titan M with Only One Byte

blog.quarkslab.com

1–10 of 84 posts

Re: Attacking Titan M with Only One Byte

#2
This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline.

Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD.

If fully compromising Google's own security chip to dump all private keys isn't worth the full $1 Million bounty, I honestly don't know what is.

Really, what would, in the mind of those on the internal committee, constitute justification for the $1 Million bounty?

Re: Attacking Titan M with Only One Byte

#4
> As a reminder, there are two conditions to perform this attack. First, we need to be able to send commands to the chip, either from a rooted device (required to use nosclient), or physically accessing the SPI bus.

> Then, we need a way to access the key blobs on the Android file system, which can be done again by being root, or with some exploit to bypass File Based Encryption or the uid access control.

Re: Attacking Titan M with Only One Byte

#7
post #5
post #3

For a moment I thought this is something related to the anime

Myself pulled in hoping for a historical tale of attacking vulnerabilities in Titan ICBMs.

Just curious - if the usage of acronym here a soft-euphemism? (So that only those who knew or care to know gets it)

edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons:

  1. Discussing "nukes" openly where I come from would raise some eyebrows.

  2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.

Re: Attacking Titan M with Only One Byte

#8

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

Remote 0-day onto all google internal infra?

Re: Attacking Titan M with Only One Byte

#9
post #5

Earlier quoted context omitted.

Myself pulled in hoping for a historical tale of attacking vulnerabilities in Titan ICBMs.

Just curious - if the usage of acronym here a soft-euphemism? (So that only those who knew or care to know gets it) edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons: 1. Discussing "nukes" openly where I come from would raise some eyebrows. 2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.

I don't think so, people could just say "nukes" but there are plenty of nukes that aren't capable of hitting targets halfway around the world. ICBM seems like the fastest way of saying "nukes that can hit stuff really far away" while also making a distinction from sub launched and cruise missile launched nukes.
Post reply on HN