Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  global AES-CCM key that Philips uses to encrypt and authenticate new firmware
Who on earth authenticates firmware through AES. Even Sony realizes that doesn't work.

(I can already imagine how the idiots fixed this: by drawing another set of bytes for a new "authentication" key..)



It's theoretically sound with a good HSM. But agreed, I'd rather rely on getting a sound software implementation of an asymmetric signature scheme than rely on protecting a symmetric key with hardware.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: