[onerng talk] install & access

Paul Campbell paul at taniwha.com
Wed Nov 5 18:10:16 GMT 2014


On Wed, 05 Nov 2014 13:00:50 ianG wrote:
> > if it were all 0s I could create a compressed (RLL for example) image
> > that 
> > could easily be embedded in another bogus set of firmware
> 
> not sure how that works?  Oh, you're talking about compressing the
> entire thing, then uncompressing it internally.  Got it.

yes

> Isn't the entire package signed? 

yes

> I'm assuming here that any flashing
> will require the new package to be signed by a key bedded into to the
> non-flashable code?

you can put your own code in there without signing it with my key (it's open 
source and hackable after all) - the system code wont start rngd  and will log 
the 'bogus' code, you can disable that check manually if you want to run your 
own firmware. 

	Paul


More information about the Discuss mailing list