Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> but to trust processes on the same system with the plain text

I don't know if that is necessary from what the details are showing.

It looks like there are two dummy files that act are used to stream data between the two OSes meaning the phone does not necessarily have unlimited access.



But surely whatever data the phone is piping to and from those dummy files can be read while it's still plaintext?


The distinction is that random access to the files need not be provided.

If I give your phone access to /usr/private_key.txt then the OS has total control. If I instead give you a way to sign messages then the OS has much weaker ability to control (obviously some amount if the device is connected and capable of signing).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: