• About
  • Advertise
  • Privacy Policy
  • Contact
Android Kenya
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
Android Kenya
No Result
View All Result
Home News

Report: Samsung shipped 100 million phones with flawed encryption

Naftaly Kariuki by Naftaly Kariuki
March 3, 2022
in News
0
Samsung commits to updating Galaxy Note 20 and Note 20 Ultra across 3 generations of Android versions
FacebookTwitterWhatsApp

A group of academics from Tel Aviv University in Israel have reported that a number of Samsung Android-based phones were shipped to users with design flaws that allowed the extraction of secret cryptographic keys.

The researchers in a paper they prepared titled “Trust Dies in Darkness: Shedding Light on Samsung’s TrustZone Keymaster Design” explain how they arrived at their conclusions. The paper is also scheduled for presentation at Real World Crypto and USENIX security expo that will take place later this year.

Let us get into the details to get a better understanding of how all these work and where Samsung might have messed up in their implementation compared to other Android OEMs.

Android smartphones by large use Arm-compatible silicon and rely on a Trusted Execution Environment (TEE) that is supported by TrustZone technology from Arm to keep security functions separate from normal applications.

This is to keep users’ information safe, among other things, and to also ensure the apps a user interacts with do not have the ability to alter how the Android operating system is fundamentally supposed to work. Basically, normal apps should not have access to things such as a device’s drivers or even passwords that you have saved to log in to a different application or website.

These TEEs do not use Android, but instead have their own operating system called TrustZone Operating System (TZOS). It is here that the onus then falls on manufacturers to implement their cryptographic functions to keep user information and by large their devices safe from would-be attackers.

READ:  Samsung won't be swapping Google Search for Microsoft's Bing as earlier alleged - WSJ

Samsung implemented a system using a tool called Keymaster TA that was responsible for carrying out cryptographic operations including key generation, encryption, attestation, and signature creation in the secure environment of the TEE. Once the data is encrypted and deemed safe to use by the Keymaster TA, the results would then be used in the Android environment that users and normal applications have access to.

By operation, the Keymaster TA creates the cryptographic keys, which are then wrapped by AES-GCM (an encryption algorithm) then stored in the file system of the Android environment. This format should be unreadable to anyone and can only be decrypted in the secure environment of the TEE.

However, the researchers from Israel report that this implementation was not carried out correctly in the Samsung Galaxy S8, S9, S10, S20, and S21 smartphones. As a result, they were able to reverse engineer the Keymaster tool in these devices and decrypt the keys that were being protected.

The researchers were also able to take advantage of the flaw in Samsung’s implementation to bypass FIDO2 WebAuthn, which is a way to use public-key cryptography, instead of passwords, to register for and authenticate to websites.

In total, the researchers estimate a total of 100 million Samsung devices were vulnerable when they first made the discovery last year. They have since then shared their findings with the South Korean company which has rolled out two updates to the affected devices, effectively patching the flaw.

They conclude their paper by advising a different encryption algorithm other than AES-GCM should be used moving forward, to avoid a reoccurrence of a similar vulnerability.

Join our Telegram channel
Previous Post

Oppo’s latest fast-charging tech iteration sees devices go from 1% to 50% in 5 minutes

Next Post

Samsung’s flagship smartphone stutters in tests ahead of local launch

Related Posts

Samsung
News

Kiswahili now supported on Samsung Galaxy devices

March 25, 2025
One-UI-7-release-date
News

Samsung confirms One UI 7 stable rollout from April 7: Here’s when Kenyan Galaxy users can expect it

March 19, 2025
Samsung Galaxy S25+ review
Reviews

Samsung Galaxy S25+ review

March 19, 2025
Next Post
Samsung Galaxy S22 series announced, available for pre-order in Kenya on March 1st

Samsung's flagship smartphone stutters in tests ahead of local launch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

  • Trending
  • Comments
  • Latest
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

May 5, 2025
Tecno Spark 3 Pro-10

How to fix OTG connected pop-up error on Tecno phones

July 28, 2019

Oppo A60 review: Rugged darling

June 10, 2024
Oppo Reno8 T review: High praise

Oppo Reno8 T review: High praise

February 28, 2023
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

0
Telegram-Android-Kenya

Telegram rolls out encrypted group calls, business automation, and gift upgrades

0
Oppo-A5-Pro-in-Kenya

Here’s the global average selling price of Android phones vs iPhones in Q1 2025

0
Vivo-X200-Pro

Vivo is Android’s revenue champion in Q1 2025, Samsung and Xiaomi hold ground on shipments

0
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

May 5, 2025
Telegram-Android-Kenya

Telegram rolls out encrypted group calls, business automation, and gift upgrades

May 5, 2025
Oppo-A5-Pro-in-Kenya

Here’s the global average selling price of Android phones vs iPhones in Q1 2025

May 5, 2025
Vivo-X200-Pro

Vivo is Android’s revenue champion in Q1 2025, Samsung and Xiaomi hold ground on shipments

May 5, 2025
  • About
  • Advertise
  • Privacy Policy
  • Contact

© 2025 Android Kenya

No Result
View All Result

© 2025 Android Kenya