solokeys / solo1-cli

Solo 1 library and CLI in Python
https://pypi.org/project/solo-python
Apache License 2.0
182 stars 69 forks source link

verify secure bootloader #162

Open xad21 opened 1 year ago

xad21 commented 1 year ago

is there a way to verify if a custom bootloader is on my stick?

solo1 key verify output: Register valid

Does that mean the firmware is valid and the secure bootloader is on the stick? Couldn't a man in the middle (European vendor) flash the hacker version, change something in the bootloader, and then modify it in a way that the upper output says valid?