[HN Gopher] The Keys to the Kingdom
___________________________________________________________________
The Keys to the Kingdom
Author : zacwest
Score : 23 points
Date : 2022-03-23 19:18 UTC (3 hours ago)
(HTM) web link (queue.acm.org)
(TXT) w3m dump (queue.acm.org)
| kurthr wrote:
| Hopefully, he also patched some portion of the bug that let him
| rewrite the bootloader signature verification code... or someone
| else only has to look at your update to have their own keys to
| the kingdom.
|
| One should also be sure that the signature verification is not
| based on simply an obscured symmetric key that easily allows key
| extraction and any code to be rewritten to those devices in the
| future once it is extracted. One assumes from his solution this
| isn't the case (or he'd only need one sample to get the key). You
| don't HAVE to do public/private keys, but it's the most
| convenient.
| josephcsible wrote:
| IMO, companies that build tivoized devices like these deserve to
| go out of business. This whole thing would have been a non-issue
| if they wouldn't have attempted to restrict the end-user in the
| first place.
| groby_b wrote:
| That's a nice absolutist stance to take on the Internet, but it
| doesn't really work in the real world.
|
| In any security-conscious environment, allowing updates without
| signature is not a winning move. You have to account for
| unauthorized access attempts somehow, and signed updates are a
| pretty standard way to do that.
|
| And if you have signed updates, all the openness in the world
| doesn't help you with a lost key.
| KennyBlanken wrote:
| There's not even a hint as to what the device actually was,
| but I guarantee "the right security features" were about
| protecting intellectual product, device lifespan control, and
| likely locking the customer into some completely stupid and
| unnecessary "cloud" management function. Not the customer's
| security.
___________________________________________________________________
(page generated 2022-03-23 23:00 UTC)