From: Marcel Holtmann <marcel@holtmann.org>
To: Steven Singer <steven.singer@csr.com>
Cc: cijoml@volny.cz, BlueZ Mailing List <bluez-users@lists.sourceforge.net>
Subject: Re: [Bluez-users] CSR firmware
Date: Tue, 01 Jun 2004 16:51:24 +0200 [thread overview]
Message-ID: <1086101484.4702.47.camel@pegasus> (raw)
In-Reply-To: <40BC8DC7.70809@csr.com>
Hi Steven,
> > What we need to know is the public key of the boot loader, so we can
> > check the signature of the firmware file. Actually I don't know how to
> > do that, because we don't get access to the boot loader over USB or
> > UART.
>
> I don't know of a way for you to get the public key out of the boot
> loader.
maybe over SPI, but then I don't need it anymore, because I can simply
replace the boot loader ;)
> > Is it easy to check if a firmware don't uses a signature? Will CSR
> > publish their public key?
>
> There's not much point in us publishing our public key if you can't
> read it out of the loader to check.
The only point is to check if a firmware is signed with your key.
> It's been pointed out to me that as well as trashing the module or
> compromising the radio performance, putting the wrong firmware onto a
> module could compromise the USB performance and might take down the
> USB bus or the host itself (for example, some modules have I/O lines
> connected to the USB bus, some have them connected to an external radio
> amplifier, I can't imagine a host would take too kindly to having its
> USB lines toggled at 1600 Hz).
>
> CSR is certainly not prepared to handle the volume of support calls
> that incorrect firmware is likely to generate and I suspect that the
> BlueZ developers, the Linux USB developers and Microsoft (if people
> plug their mutilated dongles into Windows PCs) are unwilling to handle
> the calls either.
>
> Signing is meant to prevent these problems. Just because some module
> manufacturers have failed to implement it correctly does not mean that
> taking firmware from one of these modules (or another manufacturer's
> web site) and putting on another is a good thing.
>
> It might be worth building a list of good module manufacturers/OEMs
> who regularly release up to date, tested and signed firmware.
>
> [I know this is a change of position from my last mail, but the more
> I think about this, the less comfortable I am about putting firmware
> on modules it wasn't designed for.]
But the problem is that some manufacturers are very lazy. With the HCI
16.x firmware you reached a point, where I would say, that your firmware
can be used without any problems. Also for newer profiles like HID and
A2DP, but earlier versions had problems. One of the most annoying thing
is if you can't use a Bluetooth HID device, because the latency is too
bad. If you use an USB dongle, I would simply say that you should buy a
new one, but in case of a notebook you really got into troubles. I've
seen that Sony provides an update for some of their notebooks and it
should be possible to extract the DFU file, but in the case of some IBM
notebooks you are lost.
However right now there is no easy way to download a new DFU file into a
CSR dongle. So even if the module/dongle/notebook manufacturer gives you
the right firmware file, you can do an update with Linux. Actually I had
written some code for it, but non of it is public at the moment and I
don't wanna publish it.
Regards
Marcel
-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g.
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click
_______________________________________________
Bluez-users mailing list
Bluez-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/bluez-users
prev parent reply other threads:[~2004-06-01 14:51 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-05-29 0:56 [Bluez-users] CSR firmware Michal Semler
2004-05-29 8:54 ` Marcel Holtmann
2004-05-29 9:08 ` Michal Semler
2004-05-30 7:14 ` Marcel Holtmann
2004-05-30 10:29 ` Michal Semler
2004-05-30 11:03 ` Marcel Holtmann
2004-05-30 11:17 ` Michal Semler
2004-05-30 12:07 ` Marcel Holtmann
2004-06-01 11:26 ` Steven Singer
2004-06-01 11:55 ` Marcel Holtmann
2004-06-01 14:08 ` Steven Singer
2004-06-01 14:51 ` Marcel Holtmann [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1086101484.4702.47.camel@pegasus \
--to=marcel@holtmann.org \
--cc=bluez-users@lists.sourceforge.net \
--cc=cijoml@volny.cz \
--cc=steven.singer@csr.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox