In brief

Why a dedicated crypto chip breaks the usual password guessing — on two devices: Galaxy Tab A8 (Unisoc, the chip over SPI) and Galaxy A06 (MTK, over I2C). In the first case a missing block of data has to be pulled out of the chip, and then the brute force can be offloaded to external computing power — but this is a theoretical chain, "suppose we intercepted control". In the second the chip itself checks the hash and issues the keys, working "like a gatekeeper", and then "we fundamentally can't do anything at the moment": the brute force cannot be offloaded, and inside there may be an attempt counter, slowdown and wiping. The result of the talk — a precise description of the wall, not a way around it. The most substantive part — the seven questions from the audience.

Key points

Tools, artifacts, technologies

There is no procedural content, but there is a direct warning to practitioners: unlocking the bootloader and reflashing destroy the data, and by the phone's own means — irreversibly; "with live phones it's better not to do that". In the questions the story of Apple and the American agency comes up, along with the appearance of a commercial tool for the iPhone — as an argument that there is no such thing as "100% security" from a vendor.

Questions from the audience

The speaker's position

An engineering lecture with no sales pitch: no name of his own product, no promises. The limitations are named outright and more than once — the black box, the counters, the risk of destroying the data, "we fundamentally can't do anything". Where there is no result, that is said out loud rather than hidden behind "work is under way"; his own terminology is flagged as his own. The conclusion for the extraction industry is pessimistic: the pace of patches is scarier than any new interfaces.

Quotes