4 ms·
I can see firmware updates being a problem. If the malware can hijack the firmware update process, then it copy itself onto the Trezor (making the device worse
by finnw 13y ago
I can see firmware updates being a problem.
If the malware can hijack the firmware update process, then it copy itself onto the Trezor (making the device worse than useless.)
I assume it will display a fingerprint of the new firmware and the user will need to press the button (like with a BTC transaction.) Still, a few users will probably be caught out by this.
Unless they Tivoize it (then the "open source" claim is rather dubious, but I think this may be the best solution anyway.)
So don't buy a used one.
- wmf 13y agoI'd Tivoize it and have a developer switch like Chromebooks. It goes without saying that switching modes must wipe the device.
- marssaxman 13y agoWhat firmware update process are you talking about?
- jzwinck 13y agoIf there is no firmware update process that may be even more reason to avoid buying a used Trezor. No process to authenticate a device of untrusted provenance, yet bad actors could still figure out a way to tamper with the firmware (see the photo on the site of the unit in development with the cover off and an extra cable attached), or replace the board entirely. A well-documented, well-understood firmware update process with mutual authentication (firmware and device must both be validated) might improve things for secondhand Trezor buyers.
- marssaxman 13y agoA validation process is a good idea but I'd still feel safer if the device were frozen with no way to update firmware. Many microcontrollers have "e-fuses" which you can blow post-manufacturing to render the program flash read-only, for example. One can also pot the board in epoxy to make tampering more difficult.
- finnw 13y agoWhat if the current firmware has a bug that allows an attacker to steal your keys?