Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What good is open source firmware when the hardware only accepts cryptographically signed proprietary blobs?


Assuming you can verify the signed blob identical to the one you can build yourself, you can verify there's no intentional back doors or unintentional security issues.

Not as good as being able to sign it yourself, but way better than not having the source.

It also prevents an attacker from hacking the hardware in a way that would persist after a full reinstall of the OS.


Yes, I agree. Source code and reproducible builds which can be cryptographically verified to be equivalent to the signed blob would go a long way towards making them trustworthy. Still denies us the freedom to modify them but at least trust could be assured.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: