None
EN
Themes from Real World Crypto 2022
['William Woodruff']
The Trail of Bits Blog
In this session, the presenters describe two critical weaknesses in TEEGRIS, Samsung’s implementation of a TrustZone OS: an IV reuse attack that allows an attacker to extract hardware-protected keys, and a downgrade attack that renders even the latest and patched flagship Samsung devices vulnerable to the first attack. That’s why we were saddened by the survey results in "‘They’re not that hard to mitigate’: What Cryptographic Library Developers Think About Timing Attacks" (slides, video, paper): of 44 cryptographers surveyed across 27 major open-source cryptography projects, only 17 had actually used automated tools to find timing vulnerabilities, even though 100% of the participants surveyed were aware of timing vulnerabilities and their potential severity.