[liberationtech] Freeze the memory out of a galaxy nexus?

Parker Higgins parker at eff.org
Thu Feb 21 10:37:03 PST 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 2/21/13 10:32 AM, Brian Conley wrote:
> Any idea why the researchers would posit that iOS devices may be
> less susceptible?

Not sure if this is what they have in mind, but this particular
technique requires a battery pop to get into fastboot mode, which
isn't quite as available on iOS devices as these Android ones.



> On Thu, Feb 21, 2013 at 10:08 AM, Steve Weis <steveweis at gmail.com 
> <mailto:steveweis at gmail.com>> wrote:
> 
> This is a good illustration how data in use is exposed to physical 
> attacks on most computing devices.
> 
> An interesting side-note is that Android phones are starting to
> ship with a hardware security module (HSM), which can be used for
> crypto operations and key storage. Duo Security is one company that
> started using the HSM to store credentials: 
> http://siliconangle.com/blog/2013/02/19/simple-to-scale-duo-security-uses-android-hardware-for-its-own-hack-resistance/
>
>  I haven't found much about the capabilities of these HSMs. It's
> not a silver bullet since they may still be key material exposed
> in memory, but I think it's a positive development.
> 

- -- 
Parker Higgins
Activist
Electronic Frontier Foundation
https://eff.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBAgAGBQJRJmlPAAoJEJQzX4iaNncJU1UP/jlg5E78XGOYu3KWpRwS6tCM
8eMXPANGvv3CVBhlL8WNe9HsdpyGOJVAvztdUUGiZ40HkYN7KXn/xY7Ar7TSsa8W
iwT/jjwbJO7WRkl8gW/MxrQJF8SAIwgzbZ9lJ2745e7MODS6qLyMaha8B/jou1ni
OMy7G907qrM4mLiSYdS8vKNJ89kDMMT04iX9phHDRHscBDot7dRhY+bAeBKV6H3W
HUG5neWGKrRNW1altAFZWdKEYobQkvC/TWRLbfcr825t+ilJjeXzGw3WFom2mkto
nKn1LLG6LTb94TK3x7ev8paecRthkpxPHjFd8aAmsEovvPzmNUr6fN538eII2jTW
oARxCDcm8A/i4swoJEBVanFAzYNCs5ADgKYQ1EUtJAhdYDTT5Ml2kfwWUTIeyynW
+pFlR+LivnfBl40ursbrYjVIk5Kgu1uY4V4pdY7JIw5JrCqiTMvAFjZrWJGaY4L/
oiMSPb4bmZGMS2J8/VgNR/NF6vapckcN3m1J6jf8jbKsyUojjWCrrfh5D3FTvULM
LAeT5ku31eV07MWQQeVIleBGbwQEp6uyY65U2uoieL0DvpRox/FNkZO1XhmcMxkr
Tok0QavnNOr0Zt4G/4MyFqPAjR3kh+W+KlGhba5Qzfz6FSj2/7/3CegET5FaV4JT
ScwShlIBQwiHzYqIaMpb
=jTAu
-----END PGP SIGNATURE-----



More information about the liberationtech mailing list