|
|
|
|
|
by transpute
472 days ago
|
|
This is not the first case of accidental reuse of example keys in firmware signing, https://kb.cert.org/vuls/id/455367 Would it be useful to have a public list of all example keys that could be accidentally used, which could be CI/CD tested on all publicly released firmware and microcode updates? If there was a public test suite, Linux fwupd and Windows Update could use it for binary screening before new firmware updates are accepted for distribution to endpoints. |
|
Using CMAC as both the RSA hashing function and the secure boot key verification function is almost the bigger WTF from AMD, though. That’s arguably more of a design failure from the start than something to be caught.