March 1, 2022, 11:29 p.m. | brooke.crothers

Security Boulevard securityboulevard.com

Millions of Samsung Android Phones Shipped with Encryption Flaw [Report]

brooke.crothers

Tue, 03/01/2022 - 15:29




Samsung failed to implement Keymaster TA (Trusted Application) properly in its Galaxy series phones. These “severe” cryptographic design flaws could let attackers extract hardware-protected keys, according to a paper describing the problem.


The flaw was first reported by The Register.


ARM processor-based Android smartphones use a Trusted Execution Environment (TEE) to implement security functions. The TEE, in turn, runs a separate, isolated, TrustZone …

android encryption flaw phones report samsung

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cyber Systems Administration

@ Peraton | Washington, DC, United States

Android Security Engineer, Public Sector

@ Google | Reston, VA, USA

Lead Electronic Security Engineer, CPP - Federal Facilities - Hybrid

@ Black & Veatch | Denver, CO, US

Profissional Sênior de Compliance & Validação em TI - Montes Claros (MG)

@ Novo Nordisk | Montes Claros, Minas Gerais, BR

Principal Engineer, Product Security Engineering

@ Google | Sunnyvale, CA, USA