Videos / Defcon / Slava Makkaveev: Hacking Xiaomi’s TEE and Attacking Mobile Payments

Slava Makkaveev: Hacking Xiaomi’s TEE and Attacking Mobile Payments

Duration: 23min 16sec Type: Presentation (lecture) Playlist: 11 of 146 in Defcon
A DEF CON 30 talk examining the security of mobile payment systems on Xiaomi smartphones powered by MediaTek chips. The speaker investigates the implementation of the Trusted Execution Environment (TEE), where cryptographic signatures for payment transactions are generated, and demonstrates how vulnerabilities in vendor-developed trusted applications can compromise the integrity of the payment system.

The presentation covers attack techniques that allow forging payment packages or disabling payment protections directly from an unprivileged Android application. Special focus is given to the internal logic of the TEE and attempts to bypass safeguards protecting services such as WeChat Pay.