Hacker News new | ask | show | jobs
by phreeza 3 days ago
Maybe its more like the hash was a well known secure hash but someone managed to extract the salt/private key/signing certificate from the camera?
1 comments

Most likely is either extracting the private key from the camera or getting the camera to sign arbitrary data. If the signing isn't part of the sensor die itself there's a bus where the image data gets transferred from sensor to signer, so an attacker can inject arbitrary data onto that bus to get it signed, even though they never actually extract the signing key.