Hacker News new | ask | show | jobs
by mooracle 142 days ago
The manufacturing paranoia is justified. I've seen IIoT setups where the contract manufacturer had full firmware access during flashing. TPM or not, if your CM has the keys at production time, you've just moved the trust boundary. What actually works: generate device credentials on-device after it leaves the factory, not during. Process design matters more than chip selection.