If they can't audit software properly I'm not going to assume they can audit hardware properly.
#1 is the only real problem; if anything, with vendor locked down black boxes you have fewer true attestation capabilities (sure there are mechanisms, but they depend on trusting the vendor). With an open chip it's easy to validate that it is wiped clean and then flash your code.
-
-
(keep in mind that the use case here is personal tokens and thus personal validation; remote attestation is desirable in other use cases but not really very compelling here)
-
- Firmware upgrade over the air... Having an upgradable FW is a must-have in terms of security. - Integrity of code is also a must-have. You can't sell Yubikey like products and asking your customers to load the code using the JTAG...
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.