Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

KeyMaster is a KMS that QM uses as such it holds (or well manages) access to encryption keys.

I'm not 100% sure if KM is only used to store "user" keys such as encryption keys for FDE or does it also has access to other keys stored on the hardware key storage such as the ones used to verify the firmware and OS images allowing you to bypass vendor restrictions that prevent running unsigned bootloaders, firmware, and OS images on the device.

That said QM's TrustZone kernel AFAIK pretty much runs as root (and somewhat even higher) so ACE vulnerabilities in it can be effectively used to execute any command with root or higher privileges regardless if you can fully "root" the phone or not.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: