{"id":32375,"date":"2019-10-31T21:46:40","date_gmt":"2019-10-31T18:46:40","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone\/"},"modified":"2019-10-31T21:46:40","modified_gmt":"2019-10-31T18:46:40","slug":"uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone","title":{"rendered":"Vulnerabilitet n\u00eb \u00e7ipat Qualcomm, q\u00eb lejon nxjerrjen e \u00e7el\u00ebsave t\u00eb mbyllur nga depoja TrustZone.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>K\u00ebrkuesit nga kompania NCC Group <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nccgroup.trust\/us\/our-research\/private-key-extraction-qualcomm-keystore\/\">zbuluan<\/a><\/noindex> <noindex>detajet<\/noindex> dobitjet<noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins#_CVE-2018-11976\">CVE-2018-11976<\/a><\/noindex>) n\u00eb \u00e7ipat Qualcomm, q\u00eb lejon t\u00eb p\u00ebrcaktohet p\u00ebrmbajtja e \u00e7el\u00ebsave t\u00eb mbyllur t\u00eb enkriptimit, t\u00eb vendosura n\u00eb enklav\u00ebn e izoluar Qualcomm QSEE (Qualcomm Secure Execution Environment), e bazuar n\u00eb teknologjin\u00eb ARM TrustZone. Problemi shfaqet n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins\">shumic\u00ebn<\/a><\/noindex> SoC Snapdragon, t\u00eb cil\u00ebt jan\u00eb tregtuar n\u00eb smartphone-t e bazuar n\u00eb platform\u00ebn Android. P\u00ebrmir\u00ebsimet q\u00eb eliminojn\u00eb k\u00ebt\u00eb problem tashm\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2019-04-01\">jan\u00eb p\u00ebrfshir\u00eb<\/a><\/noindex> n p\u00ebrdit\u00ebsimin e prillit t\u00eb Android dhe n\u00eb l\u00ebshimet e reja t\u00eb firmware p\u00ebr \u00e7ipat Qualcomm. P\u00ebrgatitja e korrigjimeve k\u00ebrkoi m\u00eb shum\u00eb se nj\u00eb vit nga Qualcomm \u2014 fillimisht informacionet p\u00ebr dob\u00ebsin\u00eb iu d\u00ebrguan Qualcomm m\u00eb 19 mars 2018.<\/p>\n<p>Kujtojm\u00eb se teknologjia ARM TrustZone lejon krijimin e ambienteve t\u00eb mbrojtura t\u00eb izoluara harduerike, t\u00eb cilat jan\u00eb plot\u00ebsisht t\u00eb ndara nga sistemi kryesor dhe ekzekutohen n\u00eb nj\u00eb procesor virtual t\u00eb ve\u00e7ant\u00eb duke p\u00ebrdorur nj\u00eb sistem t\u00eb ve\u00e7ant\u00eb operativ. Q\u00ebllimi kryesor i TrustZone \u00ebsht\u00eb mb\u00ebshtetje p\u00ebr ekzekutimin e izoluara t\u00eb menaxhuesve t\u00eb \u00e7el\u00ebsave t\u00eb enkriptimit, autentikimit biometrik, t\u00eb dh\u00ebnave t\u00eb pagesave dhe informacionit tjet\u00ebr konfidencial. Interaksioni me sistemin operativ kryesor b\u00ebhet n\u00eb m\u00ebnyr\u00eb t\u00eb t\u00ebrthort\u00eb p\u00ebrmes nj\u00eb nd\u00ebrfaqeje menaxhuese. \u00c7el\u00ebsat e mbyllur t\u00eb enkriptimit vendosen brenda nj\u00eb depo t\u00eb \u00e7el\u00ebsave t\u00eb izoluara harduerike, gj\u00eb q\u00eb, me nj\u00eb implementim t\u00eb duhur, lejon t\u00eb parandalohen rrjedhjet e tyre n\u00eb rast t\u00eb kompromitimit t\u00eb sistemit kryesor.<\/p>\n<p>Dob\u00ebsia lidhet me nj\u00eb zhvillim t\u00eb pamjaftuesh\u00ebm n\u00eb implementimin e algoritmit t\u00eb p\u00ebrpunimit t\u00eb kurbave eliptike, q\u00eb \u00e7on n\u00eb rrjedhjen e informacionit n\u00eb lidhje me p\u00ebrpunimin e t\u00eb dh\u00ebnave. Studiuesit zhvilluan nj\u00eb teknike sulmi p\u00ebrmes kanaleve an\u00ebsore, q\u00eb lejonin t\u00eb rikuperonin p\u00ebrmbajtjen e \u00e7el\u00ebsave t\u00eb mbyllur, t\u00eb vendosur n\u00eb harduerisht t\u00eb izoluara <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.android.com\/training\/articles\/keystore.html\">Android Keystore<\/a><\/noindex>. Rrjedhjet p\u00ebrcaktohen n\u00eb baz\u00eb t\u00eb analiz\u00ebs s\u00eb aktivitetit t\u00eb nj\u00ebsis\u00eb s\u00eb parashikimit t\u00eb kalimeve dhe ndryshimit t\u00eb koh\u00ebs s\u00eb qasjes n\u00eb t\u00eb dh\u00ebna n\u00eb memorie. Gjat\u00eb eksperimenteve, studiuesit treguan me sukses rikuperimin e \u00e7el\u00ebsave ECDSA me 224 dhe 256 bit nga depoja e \u00e7el\u00ebsave t\u00eb izoluara harduerike t\u00eb p\u00ebrdorur n\u00eb smartphone-n Nexus 5X. P\u00ebr t\u00eb rikuperuar \u00e7el\u00ebsin, nevojitej gjenerimi i rreth 12,000 n\u00ebnshkrimeve dixhitale, p\u00ebr t\u00eb cilin nevojiteshin m\u00eb shum\u00eb se 14 or\u00eb. P\u00ebr t\u00eb kryer sulmin u p\u00ebrdor mjeti <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nccgroup\/cachegrab\">Cachegrab<\/a><\/noindex>.<\/p>\n<p>Shkaku kryesor i shfaqjes s\u00eb problemit \u00ebsht\u00eb p\u00ebrdorimi i p\u00ebrbashk\u00ebt i komponent\u00ebve t\u00eb p\u00ebrbashk\u00ebt harduerik dhe caches p\u00ebr llogaritjet n\u00eb TrustZone dhe n\u00eb sistemin kryesor \u2014 izolimi \u00ebsht\u00eb realizuar n\u00eb nivelin e ndarjes logjike, por duke p\u00ebrdorur blloqe t\u00eb p\u00ebrbashk\u00ebta llogaritjeje dhe me mbetje t\u00eb informacionit lidhur me llogaritjet dhe adresat e kalimeve n\u00eb cache-n e procesorit t\u00eb p\u00ebrgjithsh\u00ebm. Me metod\u00ebn Prime+Probe, e bazuar n\u00eb vler\u00ebsimin e ndryshimit t\u00eb koh\u00ebs s\u00eb aksesit n\u00eb informacionin e cache-uar, \u00ebsht\u00eb e mundur t\u00eb ndjekim me sakt\u00ebsi t\u00eb konsiderueshme rrjedhat e t\u00eb dh\u00ebnave dhe shenjat e ekzekutimit t\u00eb kodit q\u00eb ka t\u00eb b\u00ebj\u00eb me llogaritjet e n\u00ebnshkrimeve digajale n\u00eb TrustZone.  <\/p>\n<p>Shumica e koh\u00ebs s\u00eb krijimit t\u00eb n\u00ebnshkrimeve dixhitale me \u00e7el\u00ebsat ECDSA n\u00eb \u00e7ipat Qualcomm shpenzohet n\u00eb kryerjen e operacioneve t\u00eb mnohjes n\u00eb cik\u00ebl duke p\u00ebrdorur nj\u00eb vektor t\u00eb inicializimit t\u00eb pandryshuesh\u00ebm p\u00ebr \u00e7do n\u00ebnshkrim (<noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Nonce\">nonce<\/a><\/noindex>). N\u00ebse sulmuesi arrin t\u00eb rikuperoj\u00eb disa bita t\u00eb informacionit mbi k\u00ebt\u00eb vektor, ka mund\u00ebsi t\u00eb kryej\u00eb nj\u00eb sulm p\u00ebr t\u00eb rikuperuar gjith\u00eb \u00e7el\u00ebsin e mbyllur. <\/p>\n<p>N\u00eb rastin e Qualcomm, jan\u00eb identifikuar dy vende t\u00eb rrjedhjes s\u00eb till\u00eb informacioni n\u00eb algoritmin e shum\u00ebzimit: gjat\u00eb kryerjes s\u00eb operacioneve t\u00eb k\u00ebrkimit n\u00eb tabela dhe n\u00eb kodin e nxjerrjes kushtore t\u00eb t\u00eb dh\u00ebnave mbi baz\u00ebn e vler\u00ebs s\u00eb bitsit t\u00eb fundit n\u00eb vektorin \u00abnonce\u00bb. Pavar\u00ebsisht pranis\u00eb s\u00eb masave n\u00eb kodin e Qualcomm p\u00ebr t\u00eb penguar rrjedhjet e informacionit p\u00ebrmes kanaleve t\u00eb jashtme, metoda e zhvilluar e sulmit lejon q\u00eb t\u00eb kalohen k\u00ebto masa dhe t\u00eb p\u00ebrcaktohen disa bits t\u00eb vler\u00ebs \u00abnonce\u00bb, t\u00eb cilat jan\u00eb t\u00eb mjaftueshme p\u00ebr t\u00eb rikuperuar \u00e7el\u00ebsat 256-bit ECDSA.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50572\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2018-11976) \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u0430\u043d\u043a\u043b\u0430\u0432\u0435 Qualcomm QSEE (Qualcomm Secure Execution Environment), \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 ARM TrustZone. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 SoC Snapdragon, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0432 \u0441\u043c\u0430\u0440\u0442\u0444\u043e\u043d\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443, \u0443\u0436\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0432 \u0430\u043f\u0440\u0435\u043b\u044c\u0441\u043a\u043e\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-32375","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2018-11976) \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u0430\u043d\u043a\u043b\u0430\u0432\u0435 Qualcomm QSEE (Qualcomm Secure Execution Environment), \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 ARM TrustZone. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 SoC Snapdragon, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0432 \u0441\u043c\u0430\u0440\u0442\u0444\u043e\u043d\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443, \u0443\u0436\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0432 \u0430\u043f\u0440\u0435\u043b\u044c\u0441\u043a\u043e\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0435 \u043a\u043b\u044e\u0447\u0438 \u0438\u0437 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430 TrustZone | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2018-11976) \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u0430\u043d\u043a\u043b\u0430\u0432\u0435 Qualcomm QSEE (Qualcomm Secure Execution Environment), \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 ARM TrustZone. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 SoC Snapdragon, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0432 \u0441\u043c\u0430\u0440\u0442\u0444\u043e\u043d\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443, \u0443\u0436\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0432 \u0430\u043f\u0440\u0435\u043b\u044c\u0441\u043a\u043e\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:46:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:46:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dob\u00ebsia n\u00eb \u00e7ipat Qualcomm, q\u00eb lejon nxjerrjen e \u00e7el\u00ebsave t\u00eb mbyllur nga depoja TrustZone | ProHoster","description":"Studiuesit nga NCC Group zbuluan detajet e dob\u00ebsis\u00eb (CVE-2018-11976) n\u00eb \u00e7ipat Qualcomm, q\u00eb lejon t\u00eb p\u00ebrcaktohet p\u00ebrmbajtja e \u00e7el\u00ebsave t\u00eb mbyllur t\u00eb enkriptimit, t\u00eb vendosura n\u00eb enklav\u00ebn e izoluar Qualcomm QSEE (Qualcomm Secure Execution Environment), e bazuar n\u00eb teknologjin\u00eb ARM TrustZone. Problemi shfaqet n\u00eb shumic\u00ebn e SoC Snapdragon, t\u00eb cil\u00ebt jan\u00eb tregtuar n\u00eb smartphone-t e bazuar n\u00eb platform\u00ebn Android. P\u00ebrmir\u00ebsimet q\u00eb eliminojn\u00eb k\u00ebt\u00eb problem tashm\u00eb jan\u00eb p\u00ebrfshir\u00eb n\u00eb p\u00ebrdit\u00ebsimin e prillit","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0435 \u043a\u043b\u044e\u0447\u0438 \u0438\u0437 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430 TrustZone | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2018-11976) \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u0430\u043d\u043a\u043b\u0430\u0432\u0435 Qualcomm QSEE (Qualcomm Secure Execution Environment), \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 ARM TrustZone. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 SoC Snapdragon, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0432 \u0441\u043c\u0430\u0440\u0442\u0444\u043e\u043d\u0430\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443, \u0443\u0436\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0432 \u0430\u043f\u0440\u0435\u043b\u044c\u0441\u043a\u043e\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-izvlech-zakrytye-klyuchi-iz-hranilishha-trustzone","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:46:40+00:00","article:modified_time":"2019-10-31T18:46:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32375","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 10:33:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:59:30","updated":"2026-01-21 10:33:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32375","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32375"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32375\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32375"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32375"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32375"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}