Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

Cool attack, but the the proposed mitigations don't seem to solve the threat model.

An attacker on the supply chain can always add a part that interposes on all i/o to the secure parts. This would have the same impact, unless I'm missing something, as compromising the insecure micro. The underlying problem is that there's no cryptographically secure path between the secure element and your eyes.

Ledger's verifiable erasure scheme is pretty interesting, actually. I prototyped something similar and ultimately abandoned it due to the high complexity and bandwidth requirements. From the sounds of it the major differences were that ledger didn't attempt to wipe and then reinitialize, but instead just tried to verify know state. Might still be made to work by changing that, although good luck over a uart.



An attack on the supply chain would have to happen at the very last stages when the device is assembled, as the assembler would otherwise notice the added component. I would even dare to say that the attack on the supply chain you're describing can only be done by the device assembler itself.



Could the manufacturer perform this type of "attack" on their own supply chain?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: