Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless there is weakness in the PRNG/RNG that creates the fused key in the secure enclave itself. Which is not out of question. I am not sure why FBI didn't ask apple politely how these keys are generated in the first place.


That seems excessively unlikely to me. The phone itself wouldn't have anything to seed a PRNG with, so the random number would need to come from an embedded hardware generator or a dedicated random number device in the factory, and both of those options would have huge amounts of engineering oversight.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: