[onerng talk] Do you offer tamper-evident packaging?
Paul Campbell
paul at taniwha.com
Sun Dec 6 08:51:14 GMT 2015
On Sun, 06 Dec 2015 20:15:08 Jim Cheetham wrote:
> No, tamper-evident packaging would not protect you from component- or
> assembly-time tampering. You should distrust both the manufacturing *and*
> delivery processes, and visually inspect / verify your units yourself.
> Don't take anyone elses word for it, even ours.
yes Jim's right - our solution is to sign the firmware image and to verify
that image from outside every time the system boots, the firmware checks for
simple failures and you should visually check the board to guard against
someone adding something more complex
Paul
More information about the Discuss
mailing list