Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please, don't give them ideas.


I am just a junior dev with a minimum knowledge of cryptography. This cannot possibly be a unique or new idea. It's literally the purpose of those modules and the purpose of code signing. So what are the business reasons for why it isn't done this way? Some ideas:

0. They didn't think of it, and I just gave them the idea. Unlikely. 1. Resources required to implement this (hardware read-only keystore, crypto primitives in the bootloader, reboot scan time, backup boot image storage space plus incoming image storage space, etc) are too expensive. 2. The possibility of losing the key and having devices they mathematically can't modify without a complete recall and replacement is too terrifying. 3. They don't care relative to the effort to implement it. They talk and litigate like they care, why doesn't this message get carried down to the new product department? 4. Decision makers don't understand the difference between the "security" obfuscation measures they're being sold right now, and potential, actual mathematically secure models proposed to them. 5. They are incompetent to actually build this. They have some pretty smart people, and accomplish other impressive projects, so this seems unlikely. 6. There's a flaw in my scheme that makes it no better than existing methods that can be jailbroken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: