upvote
The github OP reports that browser-based login still works, so it'll likely be circumventable.
reply
Wouldn’t any Volkswagen keys need to cross the network to get into the Secure Enclave? Or couldn’t you exploit the Volkswagen app itself?
reply
Keys in the Secure Enclave never leave the device (or the SE for that matter) and cannot be extracted even physically.
reply
Newer devices support Remote Key Provisioning (RKP), so you still can't export keys but you can import them. (Physical attacks are still possible, just very difficult)
reply
If the data is going through the air or a wire it can be sniffed, right? Is every message signed or encrypted like ssl/tls, or is this just some kind of extra header(s)?
reply
Wrong.
reply