Conversation

Another personalized hash is sent along with Weaver token retrieved from the secure element to the TEE. TEE does the hardware bound key derivation, decrypts disk encryption key and passes it to inline decryption hardwar on modern Qualcomm, Exynos and Tensor without OS getting it.
1
1
We could split this into a dedicated article to provide more details and cover the hardware keystores, etc. GrapheneOS also has a quite useful auto-reboot feature. User chooses an amount of time the device will wait for a user profile to be unlocked before the device reboots.
1