Hacker News new | ask | show | jobs
by a257 1197 days ago
L1 has been bypassed by piracy groups for years (through social engineering). They just don't share the keys publicly because it would give their opponents an advantage. See [1].

[1] https://news.ycombinator.com/item?id=29702110

1 comments

True, I didn't realize those were l1 keys. I'll have to read up on the revocation mechanism, if there is any. I'm also wondering how those keys usually leak. Is it through vulns, or just exploiting unsecure key handling?
The Nexus 6's L1 keys were dumped through a vulnerability in Qualcomm's trusted code execution environment.

http://bits-please.blogspot.com/2016/05/qsee-privilege-escal...

https://googleprojectzero.blogspot.com/2017/07/trust-issues-...