[HN Gopher] A Gap in the TrustZone preset settings for the LPC55S69
       ___________________________________________________________________
        
       A Gap in the TrustZone preset settings for the LPC55S69
        
       Author : samaysharma
       Score  : 56 points
       Date   : 2024-02-06 07:49 UTC (1 days ago)
        
 (HTM) web link (oxide.computer)
 (TXT) w3m dump (oxide.computer)
        
       | demondemidi wrote:
       | This requires the attacker to sign an image with a private key
       | which is owned by NXP or the Oem. A much larger hack!
       | 
       | Now if they glitched the startup code before programming the vtor
       | and setting up tz, wouldn't that fault with the debugger AP
       | active?
        
         | zitterbewegung wrote:
         | It's a good advertisement or due diligence that they respect
         | security and take it seriously.
        
           | demondemidi wrote:
           | Any MCU manufacturer that wants to sell in the EU needs to
           | adhere to RED/CRA, which outlines some pretty strict
           | requirements. The implementaiton varies (e.g. PSA).
           | 
           | It's consumer protection laws and not due-diligence that
           | force this. Sure, some companies were using security to
           | differentiate, but OEMs/ODMs didn't give a f__k until
           | regulations made them. And this benefits us all.
        
       | charcircuit wrote:
       | >In the absence of a fix for this errata, we will not be using
       | the TrustZone preset data.
       | 
       | I don't understand the reason behind doing this as the non
       | security errata doesn't make it insecure to use.
        
         | steveklabnik wrote:
         | > as the non security errata doesn't make it insecure to use.
         | 
         | I am a little bit unclear as to exactly what you're asking, to
         | be honest. Could you maybe rephrase this?
        
           | charcircuit wrote:
           | I didn't understand what the downsides were in using the
           | TrustZone preset data. From my reading it sounds like it
           | provides extra security until the secure signing key is
           | compromised.
        
             | steveklabnik wrote:
             | In my understanding, the preset data only makes
             | implementing this easier, but has this issue where if you
             | use it wrong, bad things can happen. We prefer to use tools
             | that make using them incorrectly difficult, especially in
             | such a sensitive context.
        
       ___________________________________________________________________
       (page generated 2024-02-07 23:02 UTC)