Skip to main content

Posts

Showing posts from August, 2019

Example - Project Zero: Trust Issues: Exploiting TrustZone TEEs

This is good example of what a blog entry should look like This blog was originally posted by  Gal Beniamini, Project Zero at Project Zero: Trust Issues: Exploiting TrustZone TEEs Mobile devices are becoming an increasingly privacy-sensitive platform. Nowadays, devices process a wide range of personal and private information of a sensitive nature, such as biometric identifiers, payment data and cryptographic keys. Additionally, modern content protection schemes demand a high degree of confidentiality, requiring stricter guarantees than those offered by the “regular” operating system. In response to these use-cases and more, mobile device manufacturers have opted for the creation of a “Trusted Execution Environment” (TEE), which can be used to safeguard the information processed within it. In the Android ecosystem, two major TEE implementations exist - Qualcomm’s QSEE and Trustonic’s Kinibi (formerly <t-base). Both of these implementations rely on ARM TrustZone security exten