TrustZone is broken as implemented in most devices, and nobody was surprised. https://blog.acolyer.org/2017/09/21/clkscrew-exposing-the-perils-of-security-oblivious-energy-management/ …
-
Show this thread
-
Seriously, anyone who's ever looked at a SoC datasheet (and it's all accessible at *kernel* level, below TrustZone) knew this was coming.
1 reply 4 retweets 4 likesShow this thread -
Modern SoCs are way, WAY too complicated. The only way to secure them is to move all the ugly hardware mgmt bits into TrustZone itself.
1 reply 2 retweets 12 likesShow this thread -
Which of course increases your TZ attack surface. You can't have your cake and eat it too.
1 reply 2 retweets 7 likesShow this thread -
Replying to @marcan42
Or have a separate CPU to do power Mgmt. And have a bunch of angry power folks yelling "but muh latencies"
2 replies 0 retweets 2 likes
Power mgmt isn't the only problem. For example, you can do fault injection shenanigans with the DRAM controller too. Lots of fun to be had.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.