I don't know whether this is true, but it's definitely possible (there are pin-compatible 64 KiB variants of the MCU). If you use the device without verifying the hardware, it's game over. To prevent Evil Maid attacks, that means checking at EVERY use.https://www.reddit.com/r/ledgerwallet/comments/86b7dk/important_to_everyone_who_bought_a_nano_ledger_s/ …
If the SE has a crypto accelerator and the MCU doesn't, you could cook up a benchmark/POW based on that. IO performance is irrelevant for this. I'm not saying it's a good idea (and might be defeated by overclocking/optimization), just that it's possible :-)
-
-
No, I digressed a bit and meant the timing for sending the flash contents over.
-
Yeah, I don't think the timing checks do much either. It's just a matter of designing the backdoor well enough to hide any added latency.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.