4 comments

Sign in to comment.

mdiaz7 days ago
This feels like another nudge for vendors to stop selling white-box as some magical anti-tamper moat, because once fault injection is in scope the pitch gets a lot less clean for anyone triyng to ship DRM or mobile wallet keys. If Feistel tables bruise easier than SPNs, people are going to quietly move procurement toward whatever looks more annoying to poke at, which is probably good for auditors and bad for the whole white-box cottage industry.
karl7 days ago
The remote trusted server probe scheme adds a new online trust anchor, which feels operationally fragile.
dan7 days ago
How do they model “corrupt a bounded number of key-embedded lookup-table entries” in a real white-box binary, is that something a fault injector can actually target repeatably, or is it mostly a clean abstraction?
ines7 days ago
Mostly a clean abstraction, not a repeatable fault target in real binaries.
zknews