Live data from Hacker News

Google Titan M: Hey, Google! It's time to redeem your promise.

issuetracker.google.com

1–10 of 28 posts

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#3

Only viewable signed in..

Here you go:

    Hey, Google! It's time to redeem your promise.

    Almost four years ago the Google blog post on Pixel 3's Titan M [1] stated:

    In the coming months, the security community will be able to audit Titan through its open-source firmware.

    However, as of today, the source code still is not available to the (security) community.

    [1] https://blog.google/products/pixel/titan-m-makes-pixel-3-our-most-secure-phone-yet/

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#5

Only viewable signed in..

Here you go: Hey, Google! It's time to redeem your promise. Almost four years ago the Google blog post on Pixel 3's Titan M [1] stated: In the coming months, the security community will be able to audit Titan through its open-source firmware. However, as of today, the source code still is not available to the (security) community. [1] https://blog.google/products/pixel/titan-m-makes-pixel-3-our-most-secure-phone-yet/

ha, you beat me to it by milliseconds

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#7
As an aside, this was published last week, Imagine how much they could of done if they didn't have to do blackbox fuzzing, and how many holes in the device would of been closed.

"Attacking Titan M with Only One Byte" [0]

> ...Titan M, a security chip introduced by Google in their Pixel smartphones, starting from the Pixel 3. In this blog post, ...we show how we found this vulnerability, using emulation-based fuzzing with AFL++ in Unicorn mode. Then, we go over the exploitation and its inherent challenges, that eventually led us to obtain code execution on the chip.

[0] https://blog.quarkslab.com/attacking-titan-m-with-only-one-b...

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#8
I’m convinced that any project named Titan will fail to ship (or fail immediately after shipping, as in the most famous instance). Apple’s car project was Titan, Facebook’s gmail killer was Project Titan, I think Activision Blizard had a Titan. Google has this, but I don’t even think it’s their first Titan to not ship, I’m blanking on the other. (Edit: Google’s defunct internet drone project was Titan)

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#9

As an aside, this was published last week, Imagine how much they could of done if they didn't have to do blackbox fuzzing, and how many holes in the device would of been closed. "Attacking Titan M with Only One Byte" [0] > ...Titan M, a security chip introduced by Google in their Pixel smartphones, starting from the Pixel 3. In this blog post, ...we show how we found this vulnerability, using emulation-based fuzzing…

I've talked with security professionals who have told me they prefer to not have source so that they don't get lazy. The bugs you find via black box methods aren't always the same you would find through scanning the code. Assuming the attacker also lacks source, you're better off finding the bugs they would find through similar methods. I don't work in security so I don't know if this is a commonly held belief.

Re: Google Titan M: Hey, Google! It's time to redeem your promise.

#10
I'm curious if this is a legally binding promise in any major jurisdiction.

E.g., can someone on the U.S. sue Google for specific performance to uphold that promise?

I'm not talking about suing for monetary compensation, or accepting an out-of-court settlement. I'm talking, full-strength, possibly precedence-setting, fulfillment of that promise in federal court?

I would so contribute to a legal fund for that, especially with the stipulation that my money must be returned if an out-of-court settlement were reached.

Post reply on HN