1. 12 Jul, 2016 2 commits
    • Paul Crowley's avatar
      Run secdiscard on encrypted key and key blob too · beb33a67
      Paul Crowley authored
      Don't rely on cryptographic binding of secdiscard to key; securely
      delete the other information needed to reconstruct the key too.
      
      Bug: 26021231
      Change-Id: If03d2c051b0ec2fdcb5c6f70bde7e3287424f216
      beb33a67
    • Paul Crowley's avatar
      Zero out blocks if BLKSECDISCARD fails · 2143ee8d
      Paul Crowley authored
      On a device where we can't BLKSECDISCARD sectors, we "overwrite" them
      with zeroes. This changes the FTL to remap those sectors to new
      locations.  With this done, the old contents are accessible only given
      a compromise of flash firmware or a die level attack.
      
      Bug: 26021231
      Change-Id: Ia065921389886fac1ba456c19c138187237c2561
      2143ee8d
  2. 22 Jun, 2016 1 commit
  3. 27 May, 2016 1 commit
  4. 23 May, 2016 1 commit
  5. 18 May, 2016 1 commit
  6. 17 May, 2016 1 commit
  7. 11 May, 2016 1 commit
  8. 10 May, 2016 5 commits
  9. 09 May, 2016 1 commit
  10. 06 May, 2016 1 commit
    • Paul Crowley's avatar
      Two phases to set the password for disk encryption · 92c5eeb4
      Paul Crowley authored
      In one phase, we make the new password work, and in the second we make
      it the only one which works ("fixation"). This means that we can set
      the password in Gatekeeper between these two phases, and a crash
      doesn't break things. Unlocking a user automatically fixates the
      presented credential.
      
      Bug: 28154455
      Change-Id: I54623c8652f0c9f72dd60388a7dc0ab2d48e81c7
      92c5eeb4
  11. 29 Apr, 2016 2 commits
  12. 27 Apr, 2016 2 commits
  13. 25 Apr, 2016 4 commits
  14. 19 Apr, 2016 3 commits
  15. 18 Apr, 2016 2 commits
  16. 15 Apr, 2016 2 commits
  17. 08 Apr, 2016 1 commit
  18. 07 Apr, 2016 2 commits
  19. 31 Mar, 2016 1 commit
  20. 29 Mar, 2016 1 commit
  21. 17 Mar, 2016 1 commit
  22. 11 Mar, 2016 3 commits
  23. 10 Mar, 2016 1 commit