Google Titan M: Hey, Google! It's time to redeem your promise.
issuetracker.google.com
Google Titan M: Hey, Google! It's time to redeem your promise.
1–10 of 28 posts
Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#2Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#3Only viewable signed in..
Hey, Google! It's time to redeem your promise.
Almost four years ago the Google blog post on Pixel 3's Titan M [1] stated:
In the coming months, the security community will be able to audit Titan through its open-source firmware.
However, as of today, the source code still is not available to the (security) community.
[1] https://blog.google/products/pixel/titan-m-makes-pixel-3-our-most-secure-phone-yet/Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#4Only viewable signed in..
Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#5Only viewable signed in..
Here you go: Hey, Google! It's time to redeem your promise. Almost four years ago the Google blog post on Pixel 3's Titan M [1] stated: In the coming months, the security community will be able to audit Titan through its open-source firmware. However, as of today, the source code still is not available to the (security) community. [1] https://blog.google/products/pixel/titan-m-makes-pixel-3-our-most-secure-phone-yet/
Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#6Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#7"Attacking Titan M with Only One Byte" [0]
> ...Titan M, a security chip introduced by Google in their Pixel smartphones, starting from the Pixel 3. In this blog post, ...we show how we found this vulnerability, using emulation-based fuzzing with AFL++ in Unicorn mode. Then, we go over the exploitation and its inherent challenges, that eventually led us to obtain code execution on the chip.
[0] https://blog.quarkslab.com/attacking-titan-m-with-only-one-b...
Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#8Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#9As an aside, this was published last week, Imagine how much they could of done if they didn't have to do blackbox fuzzing, and how many holes in the device would of been closed. "Attacking Titan M with Only One Byte" [0] > ...Titan M, a security chip introduced by Google in their Pixel smartphones, starting from the Pixel 3. In this blog post, ...we show how we found this vulnerability, using emulation-based fuzzing…
Re: Google Titan M: Hey, Google! It's time to redeem your promise.
#10E.g., can someone on the U.S. sue Google for specific performance to uphold that promise?
I'm not talking about suing for monetary compensation, or accepting an out-of-court settlement. I'm talking, full-strength, possibly precedence-setting, fulfillment of that promise in federal court?
I would so contribute to a legal fund for that, especially with the stipulation that my money must be returned if an out-of-court settlement were reached.