It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Samsung botched encryption Samsung botched encryption
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Samsung botched encryption
Reply
 
Thread Tools
Old 28th February 2022, 04:48   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,797
Stefan Mileschin Freshly Registered
Default Samsung botched encryption

From the 2017 Galaxy S8 on up to last year's Galaxy S21

Samsung apparently shipped more than 100 million of its smartphones with the encryption borked.

Models ranging from the 2017 Galaxy S8 on up to last year's Galaxy S21 were shipped with design flaws which could have let attackers siphon the devices' hardware-based cryptographic keys.

The flaws were spotted by boffins at Tel Aviv University found what they called "severe" cryptographic design flaws that could have let attackers siphon the devices' hardware-based cryptographic keys: keys that unlock the treasure trove of security-critical data that's found in smartphones.

The cyber attackers could even exploit Samsung's cryptographic missteps -- since addressed in multiple CVEs -- to downgrade a device's security protocols. That would set up a phone to be vulnerable to future attacks: a practice known as IV (initialisation vector) reuse attacks. IV reuse attacks screw with the encryption randomization that ensures that even if multiple messages with identical plaintext are encrypted, the generated corresponding ciphertexts will each be distinct.

The design flaws ironically were in devices that use ARM's TrustZone technology which is hardware support provided by ARM-based Android smartphones for a Trusted Execution Environment (TEE) to implement security-sensitive functions.

https://fudzilla.com/news/54434-sams...hed-encryption
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sony apologizes for botched PlayStation 5 pre-orders Stefan Mileschin WebNews 0 21st September 2020 11:04
Botched update crashes hundreds of Netherlands police ankle monitors Stefan Mileschin WebNews 0 13th May 2019 08:48
Microsoft to automatically remove botched updates Stefan Mileschin WebNews 0 14th March 2019 11:17
Air force peeved after Lockheed Martin botched GPS satellite testing Stefan Mileschin WebNews 0 15th February 2017 05:24
GuardKey USB Encryption Dongle Makes Military-Grade Encryption as Easy as PnP Stefan Mileschin WebNews 0 27th January 2016 09:20
Botched database leaks records for 191 million voters Stefan Mileschin WebNews 0 29th December 2015 07:57
Bitcoin miners create invalid currency after a botched upgrade Stefan Mileschin WebNews 0 6th July 2015 07:46
Microsoft Re-Releases Botched AD FS Patch Stefan Mileschin WebNews 0 20th August 2013 09:46
Why Most Web Services Don’t Use End-to-End Encryption Stefan Mileschin WebNews 0 3rd July 2013 06:51
Best Buy Issues Apology for Botched Online Orders Stefan Mileschin WebNews 0 26th December 2011 06:23

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 16:42.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO