Why are crypto/smartcard ICs (for example ATECC608) always so poorly documented / NDA-walled? The software/networking space is very open (TLS, IPSec, etc) and use of a proprietary cipher vs something like AES is massively frowned upon. So why is sec-by-obscurity OK in HW??
-
-
Interesting perspective. Are missing comments considered missing code in the spirit of "fully" open source? I wonder what
@MicrochipTech has to say, given this conversation mentions their ECC608 crypto chip. - Show replies
New conversation -
-
-
This seems peculiar to me. If you never made the code comments, or documented the comments elsewhere (e.g., internal docs or wiki) this would suddenly not be an issue? Likewise if you "generated" the code by hand versus using a tool and some template? Odd.
-
It's not community-friendly to throw generated files out there as OSS (or a file with nameless registers or cryptic code)... But it seems a stretch to say its a *violation* to publish code that compiles to the same exact binaries as its internal version without its metadata.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.