3 ms·
Does this allow users to install custom OSs on devices with verified boot chains like game consoles and phones?
by baroffoos 7y ago
Does this allow users to install custom OSs on devices with verified boot chains like game consoles and phones?
- vermilingua 7y agoIf I’m reading this correctly, it means the private key of a certificate is leaked during generation. Boot chains rely on the verification of certificates and signed data, not signing. So no.
- baroffoos 7y agoSo this lets you grab the key on your own device which is used to encrypt the storage but not the OEM key used to sign the firmware image?
- dlgeek 7y agoAlmost. s/encrypt the storage/sign the remote attestation document/. Storage would be encrypted with a symmetric AES key, this only leaks asymmetric ECDSA signing keys
- dlgeek 7y agoNo. There are two different things, Secure Boot (which prevents the device from running unsigned software) and Trusted Boot (where the device can run anything but can prove to a remote party that it's running a specific software). Because this would only leak private keys inside the device, you can only attack Trusted Boot (where producing trusted signatures is important), not Secure Boot (which only verifies signatures that were produced elsewhere).