Live data from Hacker News

Serious flaws in the way Samsung phones encrypt key material in TrustZone

twitter.com

1–10 of 91 posts

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#4
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

Their entire value proposition (as marketed by themselves) is as an alternative to Apple.

For some people that is enough.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#7
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

It gives me the impression that, even though I paid good money on it, Samsung doesn't see me as owner and will leech as much private data off me as they possibly can.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#8
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

Was in their ecosystem for about four years before going to Google Pixels - I find your experience to be very true. It was truly night and day.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#9
post #2

I used a Samsung phone for a few months, it gave me the strong impression that they really don't know how to develop software properly.

Was in their ecosystem for about four years before going to Google Pixels - I find your experience to be very true. It was truly night and day.

> before going to Google Pixels

Which isn't any better IMO. Most recent Pixels have been a buggy mess from launch. Google doesn't see to give a damn about the quality of their devices which is especially bad considering they come at flagship prices.

On the other side, my mom's cheap Samsung A52 has been great so far.

Re: Serious flaws in the way Samsung phones encrypt key material in TrustZone

#10
post #6

I personally don't like how it's possible to store data on my device without me being able to access the data. Also most of the time these keys are used for DRM. So... good IMO.

Exactly my first thoughts. Key is derived from "user-controlled data". That makes sense, it's my phone, isn't it? Why would the phone need to encrypt data in a way that the user can't access it.
Post reply on HN