So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
If they can't audit software properly I'm not going to assume they can audit hardware properly.
-
-
It sounds like a bad faith debate... Roca is concerning, but: - Even if CC are not perfect, they are just the best framework to ensure high level of security - CC labs are clearly better auditing security than any other org - Roca remains complex, took several years of research
-
At the end, the vendor patched it. Impacted products were known since they went through certification, devices on the field have been recalled and replaced...
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.