18 ms·
I find this a really interesting take. Wouldn’t someone be able to produce his own FIDO key that can send two transactions with the same sequence number though?
by dieortin 6y ago
I find this a really interesting take. Wouldn’t someone be able to produce his own FIDO key that can send two transactions with the same sequence number though?
- dandanua 6y agoYes, there should be a defense against device simulations. For example, a manufacturer can insert its root private key in the devices and use it for additional signing.
- spiorf 6y agoSo the manufacturer must have the private keys copied onto every device, so that key must be present and cleartext on every production line. And at the same time it must prevent leaking of such key. Not to mention that leaking of such key could happen from the hardware too.