Nitrokey / nitrokey-pro-firmware

Firmware for the Nitrokey Pro device
GNU General Public License v3.0
118 stars 21 forks source link

Update security #41

Closed samuel3d1 closed 6 years ago

samuel3d1 commented 6 years ago

Hi,

I am looking for some information about the security of the update mechanism for nitrokey.

Here is one of the questions that come to mind after learning about the possibility to m do firmware updates:

What measures will prevent an aversary to flash a manipulated firmware to the nitrokey. Assuming an aversary has gained access to my system, I want nitrokey to prevent them from getting my privat keys and data. If the firmware can be manipulated, I don't see how this can be effectively prevented.

jans23 commented 6 years ago

The firmware of the Nitrokey Pro can't be updated. Firmware updates of Nitrokey Start and Nitrokey Storage are password protected.