|
|
|
|
|
by monocasa
2304 days ago
|
|
Wow, I normally am all about how google handles security issues (they get dragged through the mud for some Project Zero stuff), but this def did not get handled well. Super unclear communication, starting with "you're just using it wrong", more than six month turn around, and even then at the end no clear explanation of what went wrong with someone who was collaborating with you? That's amateur hour security. |
|
Since the source code isn't available for scrutiny (though Google has promised firmware transparency [2]), it is kind of difficult to tell what really went wrong in the current reported case and what else possibly could go wrong given the use-cases for it are far-reaching and sensitive: Google has advocated StrongBox as a trustable companion that could be used to attest user actions on medical devices [3], for instance; or for use as an Identity verificafion for documents such as Driving Licenses and Passports.
[0] https://www.youtube-nocookie.com/embed/30jNsCVLpAE
[1] https://www.youtube-nocookie.com/embed/fE2KDzZaxvE
[2] https://www.youtube.com/watch?v=0uG_RKiDmQY?t=33m
[3] https://android-developers.googleblog.com/2018/10/android-pr...