Conversation

This especially affects used phones. How does a non-technical buyer know whether it is pre-rooted/jailbroken or not?
Quote Tweet
The 'returned product attack' here - buy, replace the firmware, return and hope someone else buys it - is a real-world evil maid attack, and speaks very much to why we need secure boot on IoT systems. Supply chain security is more complex that 'just' up to FOB delivery. twitter.com/CANcrypt/statu…
2
8
Replying to
Thought about doing this as a research project many many years ago, but decided it didn't have research value and would likely be a lot of trouble to actually do. This was after buying heaps of used Android phones on eBay and finding all kinds of things on them.
2
Replying to and
The ideal case would be for sending a phone through the mail, where the person sending it sets up pairing with the person receiving it before sending it. That gives it the full strength it's meant to have and something similar could be done for iOS with hardware-backed keys.
1
Show replies
One thing it's missing is more information about the firmware rather than only the focus on the OS. It would be nice to receive versions of various firmware components in the signed output too, but it'd need some way of including hardware-specific extended versions for that.