Hacker News new | ask | show | jobs
by timando 1361 days ago
It would have to hash to the same value as app A
1 comments

The device is not checking app's hash tho, it has no way to verify that the usb frame containing that hash is really from app A
The app runs on the USB device. The code is loaded from the host, and if it hashes to the correct value, it will be able to access the secrets on the Tillitis.