ewx: (Default)
Richard Kettlewell ([personal profile] ewx) wrote in [personal profile] mjg59 2017-04-09 08:49 am (UTC)

Without having looked inside the signed images at all and only having superficially looked at version_info.json, I don't see anything that obviously contributes to freshness checking; if this is indeed missing then it might be possible for an attacker to silently prevent legitimates updates reaching the device or (depending what other checks are done elsewhere) roll firmware back.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org