Rairii,
@Rairii@haqueers.com avatar

https://uefi.org/sites/default/files/resources/Evolving%20the%20Secure%20Boot%20Ecosystem_Flick%20and%20Sutherland.pdf

"some OEMs have lost their PK private keys"

"some OEMs shipped broken db-update implementations, that in some cases cause an outright brick"

why am I not surprised

demomantf2,

@Rairii the latter thing reminds me of when nintendo bricked a bunch of wiis because they tried to update boot2 and didn't test it 💀

Rairii,
@Rairii@haqueers.com avatar

@demomantf2 ES_ImportBoot was tested a lot on devkits, broadon eventually fixed the bug at some point

but they never really did network updates much (the majority of devkits were updated via wads on dev-signed update .isos), and without haxx there was no way to know if you were running a buggy ES until it was too late

jernej__s,

@Rairii On one hand, it's completely expected. On the other hand, how do you manage to do that‽

Rairii,
@Rairii@haqueers.com avatar

@jernej__s by deleting the only copy

and for the "broken db update" thing:

"why would we ever need to test that"

Rairii,
@Rairii@haqueers.com avatar

@jernej__s watching the actual talk and they mention "OEM's PK expired so they can't sign anything with it"

hahaha, just patch your signing tools to ignore expiry date, people have done that already, surely that would work in some of those cases

(do HSMs care on the hardware about expiry date? it's my understanding that they wouldn't have the actual x509 cert, just the keypair of which the privkey can only be used to sign stuff?)

jernej__s,

@Rairii Ah, the certificates were only issued for a 10-year period, so we're seeing the fallout of that now.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • anitta
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • provamag3
  • tester
  • Leos
  • megavids
  • JUstTest
  • All magazines