|
|
|
|
|
by lxgr
337 days ago
|
|
Definitely, no reference implementation should have security bugs. But do you know if Oracle's reference implementation for Java Card is one using on-card or off-card verification, or more generally is assuming installs from only trusted sources? There are many Java Card applications where the assumption of all bytecode being trusted is reasonable, especially if all bytecode comes from the issuer and post-issuance application loading isn't possible. Of course, that would be a complete mismatch for an eUICC. |
|
[1]: https://security-explorations.com/java-card.html#faq