That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…
or Apple just implemented this "API" for them, because they've asked nicely
That's the problem with this sort of security through obscurity; it's only secure as long as the people who know about it can keep it secret.