.@dangoodin001 In regards to http://arstechnica.com/security/2016/07/androids-full-disk-encryption-just-got-much-weaker-heres-why/ …, it's only the OEM / OS vendor with the signing keys. Google only has those for Nexus.
-
-
Replying to @CopperheadOS @dangoodin001
you have to trust more than 1 company with device security (yes), FDE key is stored in software (yes). LGTM.
2 replies 0 retweets 0 likes -
Replying to @dguido @dangoodin001
Google doesn't have the keys. Qualcomm doesn't have the keys. There is no second party able to flash firmware or OS.
2 replies 0 retweets 0 likes -
Replying to @CopperheadOS @dangoodin001
As I said, people frequently assume that Google is in control. They're not. It's the OEM. This is news to many.
1 reply 0 retweets 1 like -
Replying to @dguido @dangoodin001
Yes, and that assumption should be corrected, but not by spreading another misunderstanding that also isn't correct.
1 reply 0 retweets 0 likes -
Replying to @CopperheadOS @dangoodin001
"Since the key is available to TrustZone, the hardware makers can simply create and sign a TrustZone image"
2 replies 0 retweets 0 likes -
Replying to @dguido @dangoodin001
The article claims Google has access, which isn't true, and it implies that Qualcomm might have access - they don't.
1 reply 0 retweets 0 likes -
Replying to @CopperheadOS @dangoodin001
It does not imply Qualcomm has access.
1 reply 0 retweets 0 likes -
It explicitly says that Qualcomm does not have access.
1 reply 0 retweets 0 likes -
Replying to @dguido @dangoodin001
The article doesn't do that. It presents a claim that it does, and then in parentheses notes Qualcomm disagrees.
2 replies 0 retweets 0 likes
Ok, so then Dan Goodin did his job in reporting that discrepancy, yes?
-
-
Replying to @dguido @dangoodin001
Disagree that journalism should be about multiple sides in cases when there's a very clear factual truth to discover.
1 reply 0 retweets 0 likes -
Replying to @CopperheadOS @dangoodin001
You have to report the initial speculation, but I think "factual truth" is exactly what Dan reported.
1 reply 0 retweets 0 likes - 5 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.