|
|
|
|
|
by hdevalence
837 days ago
|
|
> by mitming the bus between the iris scanner and the rest of the unit, and making it report fresh unique scans Hmm, I wonder if the worldcoin team also thought of that possibility? (Yes, they did, the iris processing is done inside a hardware enclave so that the obvious attack is not possible) https://whitepaper.worldcoin.org/technical-implementation I am broadly anti-Worldcoin but it is reasonably competently executed at a technical level. It would be good to understand what they actually did before declaring it to be impossible. |
|
The SoC they're using, the Jetson Xavier NX, is a cousin of the very thoroughly pwned (secure enclaves and all) TX1.
Further, they don't describe how the busses connecting the sensors to the SoC are encrypted and/or authenticated, which leads me to believe that they are not.
Intel gave up on shipping SGX in consumer devices because (imho) shipping secure enclaves directly to "adversaries" (the consumer being an adversary under the SGX threat model) proved too difficult to maintain.