Encryption #348

Closed
positix opened this Issue Jul 20, 2016 · 6 comments

Comments

Projects
None yet
3 participants
@positix

positix commented Jul 20, 2016

Hi. Couple of questions about encryption in CopperheadOS

  1. Do you use 256-bit encryption for the master key? The documentation says its optional for OEMs to go higher than 128. https://source.android.com/security/encryption/'

  2. Do you disable TRIM? Google enables it since Android 5.0 though its disabled on desktop Linux for security. When its on, TRIM leaks data that was encrypted before when the user deletes it.
    http://asalor.blogspot.com/2011/08/trim-dm-crypt-problems.html

  3. I saw somewhere that CopperheadOS defends against the TEE keystore extraction. is this true?

@thelifeofjay

This comment has been minimized.

Show comment Hide comment
@positix

This comment has been minimized.

Show comment Hide comment
@positix

positix Jul 22, 2016

I'll follow guidelines, but I would really like some feedback for my questions.

I am not fond of contact forms because they are not transparent like forums. No one else with the same concerns gets to know if its been asked before or what your response was.

positix commented Jul 22, 2016

I'll follow guidelines, but I would really like some feedback for my questions.

I am not fond of contact forms because they are not transparent like forums. No one else with the same concerns gets to know if its been asked before or what your response was.

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Jul 22, 2016

Contributor

No one else with the same concerns gets to know if its been asked before or what your response was.

That's assuming they look for answer, but the answer to those questions is already available. The issue tracker isn't going to be used to provide support. It's for tracking bugs and enhancements.

Contributor

thestinger commented Jul 22, 2016

No one else with the same concerns gets to know if its been asked before or what your response was.

That's assuming they look for answer, but the answer to those questions is already available. The issue tracker isn't going to be used to provide support. It's for tracking bugs and enhancements.

@positix

This comment has been minimized.

Show comment Hide comment
@positix

positix Jul 23, 2016

Alright. Saw some answers on your tech overview.

Please address question 2 and 3. You mention TEE, but its not clear if what the latest TrustZone key extraction applies to CopperheadOS, or how much damage it does.

positix commented Jul 23, 2016

Alright. Saw some answers on your tech overview.

Please address question 2 and 3. You mention TEE, but its not clear if what the latest TrustZone key extraction applies to CopperheadOS, or how much damage it does.

@positix

This comment has been minimized.

Show comment Hide comment
@positix

positix Jul 28, 2016

I checked and you, in fact, do disable TRIM. There is no discard option in fstab.

Thanks CopperheadOS guys for making us safe.

positix commented Jul 28, 2016

I checked and you, in fact, do disable TRIM. There is no discard option in fstab.

Thanks CopperheadOS guys for making us safe.

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Jul 28, 2016

Contributor

Android does TRIM via fstrim rather than discard.

Contributor

thestinger commented Jul 28, 2016

Android does TRIM via fstrim rather than discard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment