|
|
|
|
|
by jlokier
2056 days ago
|
|
Yes it does, because it's not a random third party. It's the device manufacturer. Everyone is already dependent on some level of integrity by the device manufacturer, whether they're happy with this or not, because there is no other option. That integrity might be checked. The manufacturer may be audited. Their processes and people may be background checked. Their hiring practices subject to a standard. Some of their devices may be selected at random, scrutinised, picked apart, checked by third parties, just to be sure. It's not done much, but perhaps it should be. Anyway, if that's done there is some higher level of justification in trusting the manufacturer's integrity, even if it remains a weak point. If we already have to trust the device manufacturer and/or their auditors, that makes them owning the software trust root a very different proposition compared with anyone else owning it. |
|
It might also be broken and they don't care for you and you're screwed.
Also, as was shown many a time, the manufacturer will prevent you from doing whatever you please with your own hardware, if you chose to do so. In that case, their integrity is broken by design.