logoalt Hacker News

teravortoday at 12:45 AM3 repliesview on HN

this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move.

this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).


Replies

OGWhalestoday at 4:09 AM

Not that shufflecake solves the issue you highlighted, but I found the shufflecake FAQ to be a good intro to the topic for anyone curious. It does a good job explaining the threat vectors and the relevant trade offs, in particular the TRIM and ORAM sections. It’s also just a cool project: https://shufflecake.net/

JSR_FDEDtoday at 12:49 AM

What does “block devices aren’t dumb anymore” mean?

show 2 replies
jauntywundrkindtoday at 3:55 AM

I agree that trying to outcompete seems really hard, but also:

Given what the experience of using a non-rooted phone is like, how very very tight the sandboxing is and how useless it is a General Purpose Computer that will tell you anything: I find it very hard to believe the unlocked phone is going to let you start probing firmware & snooping on hidden volumes.

This post sent my BS detector on high alert. I'm struggling to take it seriously.

show 1 reply