Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a trade-off wrt attestation privacy here - i.e. using a single root key is better for privacy?


Ideally, at least for headless server hardware, if you have physical access, you could wipe the provisioning key and replace it with your own.

Doing so should blow away the disk keys, etc.

I’ve always assumed systems that relied on a key and didn’t support that were backdoored.


Which systems support that?


with batch sizes in the millions less so, but agreed it's still a differentiating attribute. I would solve that higher up in the protocols that used it, as the initialization keys shouldn't be related to post-provisioning keys in a way that is verifiable to anyone except the OEM, again arguable, but it's a higher level protocol question imo.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: