Solana hoses down ‘inaccurate’ CertiK report on Saga phone security flaws

0

[ad_1]

A recent video from blockchain security firm CertiK has made a series of “inaccurate” claims about a potential security vulnerability in Solana’s crypto-enabled Saga phone, Solana Labs said.

In a Nov. 15 post on X (formerly Twitter), CertiK claimed the Saga phone contained a “critical vulnerability” known as a “bootloader unlock” attack, which would supposedly allow a malicious actor to install a hidden backdoor in the phone.

In a report sent to Cointelegraph, CertiK claimed the bootloader unlock would “allow an attacker with physical access to a phone to load custom firmware containing a root backdoor.”

“We demonstrate that this can compromise the most sensitive data stored on the phone, including cryptocurrency private keys,” CertiK’s report said.

However, a Solana Labs spokesperson told Cointelegraph that CertiK’s claims are inaccurate, and its video did not reveal any legitimate threat to the Saga device.

“The CertiK video does not reveal any known vulnerability or security threat to Saga holders.”

Android’s internal Open Source Project documentation shows unlocking a bootloader can be performed across a wide range of Android devices.

Solana Labs said that, to unlock the bootloader and install custom firmware, an attacker would have to go through multiple steps, which can only be performed after unlocking the device with the user’s passcode or fingerprint.

“Unlocking the bootloader wipes the device, which users are alerted about multiple times when unlocking the bootloader, so it’s not a process that can take place without users’ active participation or awareness,” Solana Labs said.

Related: Making real-world blockchain solutions possible — Solana co-founder Raj Gokal

Additionally, if anyone proceeds to unlock the bootloader on an Android device, they’re subjected to a series of warnings about the implications of the process.

If they ignore these warnings, the device will be wiped along with their private keys.

The Solana Saga phone was released in April 2022 with a price tag of $1,099. The phone offers a Web3-native decentralized application store in a bid to integrate crypto apps into tech hardware.

Four months after launch, however, Solana slashed its price to $599, following a steep decline in sales.

CertiK did not immediately respond to a request for comment on Solana Labs’ rebuttal.

Magazine: I spent a week working in VR. It was mostly terrible, however…



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
solana
Solana (SOL) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
tron
TRON (TRX) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
monero
Monero (XMR) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
Shares