Forgot your password?
typodupeerror

Comment D-Link firmware encryption - no proper signature? (Score 1) 74

"... The researchers didn't publish many technical details about their findings, except for one case concerning the extraction of the encryption key for D-Link router firmware images. ... By analyzing the corresponding variables and functions, the researchers eventually extracted the AES key used for the firmware encryption. Using that key, a threat actor can send malicious firmware image updates to pass verification checks on the device, potentially planting malware on the router. Such problems can be solved with full-disk encryption that secures locally stored images, but this practice is not common. ..."

If - apart from integrity and confidentiality - authenticity is a goal for firmware update checks (as it probably should be) then a firmware update should be protected by a private key signature and be verified by a _public_ key (and not rely on symmetric key encryption for something like that).

Slashdot Top Deals

The next person to mention spaghetti stacks to me is going to have his head knocked off. -- Bill Conrad

Working...