public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
From: Wolfgang Denk <wd@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot] Secure update of uboot devices?
Date: Fri, 30 Dec 2011 13:37:47 +0100	[thread overview]
Message-ID: <20111230123747.849B019082FA@gemini.denx.de> (raw)
In-Reply-To: <CAB+EkH4j-UoUyHb=XgDbGRncX=Oq6+3+MNjWStiuojoOYUcMPw@mail.gmail.com>

Dear Andreas,

In message <CAB+EkH4j-UoUyHb=XgDbGRncX=Oq6+3+MNjWStiuojoOYUcMPw@mail.gmail.com> you wrote:
>
> sha1sum sum is yes enough to verify that no files have been modified on the
> file system on the already installed Linux device.

It is also good enough to ensure that the files on any distribution
media have not been corrupted or modified in some way.  Of course it
dies not protect against intentional modifications.

> But my case here is if one need to update the software on the device out
> somewhere in the world we have now made a usb stick and uboot looks for
> special files first on the usb stick before it continues normal boot. How
> can one ensure that the software on the usb stick is not altered on the way
> to include some additional unwanted features?

You cannot.  Actually you would have to insure first that the U-Boot
running on that system has not been tampered with.  If I were to
attack such a system, I'd probably first install (or otherwise run) a
version of U-boot that has any such security checks disabled or
removed.

Best regards,

Wolfgang Denk

-- 
DENX Software Engineering GmbH,     MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: wd at denx.de
There is, however, a strange, musty smell in the air that reminds  me
of something...hmm...yes...I've got it...there's a VMS nearby, or I'm
a Blit.          - Larry Wall in Configure from the perl distribution

  reply	other threads:[~2011-12-30 12:37 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-12-28  7:58 [U-Boot] Secure update of uboot devices? Andreas Bäck
2011-12-28 17:53 ` Marek Vasut
2011-12-30 12:13   ` Andreas Bäck
2011-12-30 12:37     ` Wolfgang Denk [this message]
     [not found]       ` <CAB+EkH69iuEjcdKUYeX2NDw_v5bDJ6aLBbLPUN7ii7dnnAQmsg@mail.gmail.com>
2012-01-02 10:06         ` Wolfgang Denk
2012-01-06 11:24           ` Andreas Bäck
2012-01-06 19:25             ` Mike Frysinger
2012-01-06 23:20             ` Wolfgang Denk
2012-01-06 23:56       ` Kim Phillips
2012-03-17  9:25         ` Andreas Bäck
2013-01-08 21:15           ` Simon Glass

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20111230123747.849B019082FA@gemini.denx.de \
    --to=wd@denx.de \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox