I don't know whether this is true, but it's definitely possible (there are pin-compatible 64 KiB variants of the MCU). If you use the device without verifying the hardware, it's game over. To prevent Evil Maid attacks, that means checking at EVERY use.https://www.reddit.com/r/ledgerwallet/comments/86b7dk/important_to_everyone_who_bought_a_nano_ledger_s/ …
Not JTAG, but it should be entirely possible to trojan the bootloader such that it accepts legitimate firmware updates over USB, stores them, but still runs the old modified code (or even dynamically patches the new code, if it hasn't changed much).
-
-
This is a very old war to fight (and lose); this kind of thing and similar techniques have been going on for ages with hacked pay TV cards and the like. It's a cat and mouse game. Even with 32K you can always find a way to make some space and hide it.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.