02.08.2016 Views

Android Security

AnSec2.0

AnSec2.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Untrustworthy TrustZone<br />

TrustZone Vulnerabilities<br />

• Problem: TZ OS is often vendor defined, closed source<br />

– Google trying to standardize with “Trusty OS”<br />

– Qualcomm (most common) has own, and BUGGY<br />

• http://bits-please.blogspot.com<br />

– AMAZING detail of trustzone exploitation on MSM, step-by-step<br />

– Particularly as of /2015/03/getting-arbitrary-code-execution-in.html<br />

(C) 2016 Jonathan Levin & Technologeeks.com - Share freely, but please cite source!

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!