Comment by rkozik1989

9 hours ago

Serious question about phone security: do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.

>do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.

If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.

Security isn't just an absolute, it's also a multi-faceted series of defense-in-depth measures.

Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.

What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"

There are several peripherals running their own OS. Those have their access to RAM limited by an iommu and they have no direct access to the primary storage (they may have some local ROM storage for firmware). If you're asking about the other OS that runs on the application processor such as the bootloaders, trusted firmware, trusted os, etc, then no, those have a superset of access to what the primary OS running on those cores have access to. This is by design.

  • It's not just phones, either. All modern computers are full of non-architectural cores running all kinds of wacky stuff.

Yes, at least Pixels and Apple devices do (the Titan/T security chips handle disk encryption and communication and are behind IOMMU which disallows direct acces from things like modems).

What's meant by "your device's real-time OS"? Heard several variations of this questioning recently and it seems more like FUD than anything else. I presume it's a telephone game away from the fact that some modem processors have DMA access and WAN-side exploits?