Hacker News new | ask | show | jobs
by 32032141 2692 days ago
A "secure", closed source processor. Given the Ledger bootloader had a rather nasty and bluntly obvious bug in it that allowed you to bypass all of the write protection and boot any firmware, I'd give them nearly zero chance of having got anything else right.
1 comments

Let he who has never written software that had a bug throw the first stone...
Hi, I've written bootloaders before.I know that blacklisting addresses doesn't work, as many memory locations will be mapped multiple times. Strangely, most people that have worked with microcontrollers is aware of this, except for the people who wrote the closed source bootloader at ledger.
Well, since you're the expert, why haven't you written a better one? There's a huge market for this...
I don't think my threat model encompasses the safety of other people's money.
> Let he who has never written software that had a bug throw the first object Object...