Jump in the discussion.

No email address required.

I'm still unsure if this is only keys in regular application memory (e.g. you run a https server on your Mac and now a malicious actor can grab the secret keys in memory) or if this also applies to Secure Enclave keys.

The former is bad but not alarm bells ringing (to me), the later is the worst exploit that could happen.

!codecels


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

secure enclave is the antichrist

Jump in the discussion.

No email address required.

You think? I get that it can be leveraged for DRM but I think it's ultimately a useful tool.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

In theory it should require direct access to your machine and time. Having read the white papers, more likely than not, its all keys including secure enclave keys

Jump in the discussion.

No email address required.

How are they extracting the key data from the Secure Enclave if they don't touch the memory?


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

The video explains it in the later bits, he whiteboards it then does a proof of concept.

Jump in the discussion.

No email address required.

whoops, I had it assumed it was a clickbait "news" channel - didn't realize this guy was legit :marseyteehee:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Its a little hard to follow if you dont watch from about the beginning. Hes really good actually. Around the 15 minute mark he really starts diving in.

https://i.rdrama.net/images/17112537206103685.webp

https://i.rdrama.net/images/17112537208249042.webp

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.