Conversation

Trezor Model T is a great product. I bought it for hardware-based Bitcoin wallets but it's working well for SSH via trezor-agent (ed25519) and U2F. It has per-identity keys for SSH and requires auth to use U2F or an SSH identity via the touchscreen just like Bitcoin payments.
2
13
Replying to and
A mobile SoC is of course an enormously complex set of proprietary systems and they contain assorted cryptography, virtualization, verified boot and secure enclave features among other things. Phone vendors are in control of how features like TrustZone are used on a Qualcomm SoC.
1
2
Replying to and
If they want to include a bunch of enterprise management features in the Trusted Execution Environment, it's something that the hardware is capable of supporting since it supports arbitrary applets. The phone vendor controls the signing keys so they choose what will be run there.
1
1
Show replies