Re: [Suit] suit-firmware-encryption-00

Brendan Moran <Brendan.Moran@arm.com> Wed, 02 June 2021 12:34 UTC

Return-Path: <Brendan.Moran@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78DB23A4183 for <suit@ietfa.amsl.com>; Wed, 2 Jun 2021 05:34:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=WSqp/x9d; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=WSqp/x9d
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UWSx_NlF9MnX for <suit@ietfa.amsl.com>; Wed, 2 Jun 2021 05:34:45 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2059.outbound.protection.outlook.com [40.107.22.59]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A6BFA3A4181 for <suit@ietf.org>; Wed, 2 Jun 2021 05:34:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HR4KoKZrsp2cOTa8f0/uF8aK8T7HiFGEy5v09WfYCHY=; b=WSqp/x9dFUZ2Q6eSXT9cwOTBNkqcPZxA/fJzp9o8jYdM4O3rne5DGfxV3RKTy2sR0MJysxmwoe0hTxQG8x18Edp5gtiGtJz87xFdrwTMQSuxbrTxvQaJwspv7MlYjboUKudTznuk7w9037LPIfx5rIR7CxvbWRHEB2nkTVFkBEI=
Received: from AM6P194CA0036.EURP194.PROD.OUTLOOK.COM (2603:10a6:209:90::49) by AM0PR08MB4036.eurprd08.prod.outlook.com (2603:10a6:208:12c::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4173.22; Wed, 2 Jun 2021 12:34:40 +0000
Received: from AM5EUR03FT064.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:90:cafe::a) by AM6P194CA0036.outlook.office365.com (2603:10a6:209:90::49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.15 via Frontend Transport; Wed, 2 Jun 2021 12:34:40 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT064.mail.protection.outlook.com (10.152.17.53) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4150.30 via Frontend Transport; Wed, 2 Jun 2021 12:34:39 +0000
Received: ("Tessian outbound 5e4f56e125a9:v93"); Wed, 02 Jun 2021 12:34:39 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: fa02c7f6286b2b85
X-CR-MTA-TID: 64aa7808
Received: from 1a4a2dc99afc.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 269A723A-B983-4DCB-81EB-632521DC7312.1; Wed, 02 Jun 2021 12:34:30 +0000
Received: from EUR05-DB8-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 1a4a2dc99afc.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 02 Jun 2021 12:34:30 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ho+FEcG3MFIEXQFVuhZSL4lqLXav0xTVh3CLqFXRkfDvI3YBtW/F4cHcEdxac2KElOumzKQ4QV5mld3GGaM8V2Q1YMF9oqRpEbJHGb0CzCwId96sE1UG/zUREA6t6q3+WmHuNaEIV11neizvQBNHLPMM+/qmmUiAAmOq+t+L9AoZLsonUY9cDgDlDRHhRTauzMTXsVfbXPLeeWSi5Ygb7YO35XtOMVUJ5TCPmOk+wbBsRB4AN9E9TIVPleJjLmCTvjeo7HAij0KjmjhSFB1luUkPl2tmaTlGMLbuIfZGslP5X2XaSJ04DFRZ9hzkc6pAXgMOFN24UaB62z+6rElvkw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HR4KoKZrsp2cOTa8f0/uF8aK8T7HiFGEy5v09WfYCHY=; b=HKprCgr6nc1rCiw/wK6FqyqJf8SfXhtJdLcIKws+J3GsAkUeoJsncgiD4d6b3XuB//z0Rd6FRnqgNckZyYuZRXPTMjj4oSBXOta7/zDVZRj1VboQSBXWe31VP4qnO4pdPdITMKmHOAXl57PLELjw1ZZV13+k2m81osWwKnyZC5w4LOa0vqkBBjpIY4iIuSj49rfffsqJmQP4qKx7h+2Yt+m1cM4SMLBp00XxNfkqGIcnbQBoTsxQAtgjH4EzTtmSqxX7TJU7nf7CGNc1Y3rL8OexM4EMd3MIlOcz32dfxx8aHCmWLR4Bwx7J9cipUkiI6CEyV8hgL+56caDMLhcTPw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HR4KoKZrsp2cOTa8f0/uF8aK8T7HiFGEy5v09WfYCHY=; b=WSqp/x9dFUZ2Q6eSXT9cwOTBNkqcPZxA/fJzp9o8jYdM4O3rne5DGfxV3RKTy2sR0MJysxmwoe0hTxQG8x18Edp5gtiGtJz87xFdrwTMQSuxbrTxvQaJwspv7MlYjboUKudTznuk7w9037LPIfx5rIR7CxvbWRHEB2nkTVFkBEI=
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com (2603:10a6:10:1ae::11) by DB9PR08MB6826.eurprd08.prod.outlook.com (2603:10a6:10:2ac::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4173.21; Wed, 2 Jun 2021 12:34:30 +0000
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::488c:be63:d9fe:b0e0]) by DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::488c:be63:d9fe:b0e0%7]) with mapi id 15.20.4173.030; Wed, 2 Jun 2021 12:34:30 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: Dick Brooks <dick@reliableenergyanalytics.com>
CC: Hannes Tschofenig <Hannes.Tschofenig@arm.com>, Michael Richardson <mcr+ietf@sandelman.ca>, Russ Housley <housley@vigilsec.com>, "suit@ietf.org" <suit@ietf.org>
Thread-Topic: [Suit] suit-firmware-encryption-00
Thread-Index: AQHXUy5zvx3nHIfq0kuzjZIH4a2amqr9uSuAgAAS7gCAAAUmgIAAM+0AgAACh4CAAqkygA==
Date: Wed, 02 Jun 2021 12:34:29 +0000
Message-ID: <1B50DDD2-2B47-4044-B812-30BE0D80B31D@arm.com>
References: <19586.1622075797@localhost> <DBBPR08MB5915CEC125579D78C108D540FA3F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <F6C86CC2-3AF8-4CC5-BB47-AC6579DAA0C4@vigilsec.com> <13894.1622479289@localhost> <DBBPR08MB59153D31EE75D565A64B4F79FA3F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <186901d75657$0ab645a0$2022d0e0$@reliableenergyanalytics.com>
In-Reply-To: <186901d75657$0ab645a0$2022d0e0$@reliableenergyanalytics.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3654.100.0.2.22)
Authentication-Results-Original: reliableenergyanalytics.com; dkim=none (message not signed) header.d=none;reliableenergyanalytics.com; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.7.184.196]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: d593d58d-ffb2-4476-5d6a-08d925c2ca72
x-ms-traffictypediagnostic: DB9PR08MB6826:|AM0PR08MB4036:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <AM0PR08MB4036ED81142D73BE89095A26EA3D9@AM0PR08MB4036.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: yiC+qfslEaJ39HDCEYV1C4RbMZIZFscuJ00HbmBvq6opEdsZevUx8O13Ts30KenXAtnVqgGZtm6UZ4X/kiNPDRa7Im+2bJ7SAE+pgV66OC4LmDcatXAvBD3ocRoBvzoGFqOQey+orF99hpcBhjBJnAIm6XUOKoquo0Qdo3WhGr1rWZTrJ9+HcSSkOIwezu4Qfr3+jkJD+doFxC0GEX64IxLiC+H/anxtjFnIAr51s/C0L5ve2Kjzr2c00viF6hqm5hf61gG84SlW4HphhVgPgDc3UyxXjbi9mh2Ijv87CivB8c3tvNzv2m4YsbjaZj7Joj95yYmj3+u/V3x5dWif8/Igoe1/RlRr+fMm1x3hes/bFo8K0lLxUoXWCH4vtH9rA0kilZqK/nQz5h4+FjhAg9DrMk2GO9YTyyNhTovOdqoxgNJFCpoHrTqoqT03x7VpOkCAnI0g0bsnNls5H+zV3VS+QrU1CAE4A9KrM2BLNN2QieKo8kdVteOYjyXbeko6kGvDU3PRUJTF7noUer3vu/h/1ffFvKWhpweTXI4Ugix9tmNwxhuY8hcIjiFfaVKla0vxeZ7xsbsLUKQYbFwDfYPN+q5l27n7/mGNaaqX57m131lAqXkT1sQ1Wv1anEwDDP91JukN+mXo7KgWgsXm8aTaVnCbZomh7nvIHojZdaNBBIyJOrxN6DTGEUSZR/Bug1gTcfnAun0L+9DdFawkwM8ayoC5adEShD5F/+7dc6e+a67bQiNsHqTL8NnqG9aw5ObBf5v+za5dM40S7jLd2Qu631xTU+NKuva+NQvdKUDiCPuvVnNOQMW0tEfU3a2R
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBAPR08MB5576.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(136003)(376002)(39850400004)(396003)(366004)(36756003)(6506007)(53546011)(2616005)(966005)(5660300002)(33656002)(8936002)(478600001)(6512007)(6916009)(122000001)(54906003)(83380400001)(316002)(86362001)(66556008)(91956017)(66476007)(64756008)(66446008)(8676002)(2906002)(66574015)(71200400001)(6486002)(66946007)(76116006)(186003)(4326008)(26005)(38100700002)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: OZekFEwBdxNVRCceJWx6coHmUU4uoMQ7M8u1WCkPRsCKTMY34aEqUSELD0ZKCWMk1J32A34Ls+kXVVMZdst4bUB87Om0QNQgAMWyjq3A3RgUh6+3dvXlG7DE//X/5DLPrybJ6SgLgKHSKT8eXuGDJAjF/9KfPcch7FPUpVnU0spDPD0NzZxqvNHj+cY+npMy1LEJHN8ps+aMAg/V2STQSNUtVaRjUvKYD93bXG0bUWyvIz4JlEzCGk7IMCzWEf1Bjq55ZmqHSvhUc1A8AH754OBsItGgbbJfFBDcMsGeLx7lNkzAEA0pjSMyBmz+Qd259gIwkk7LIKvLDa6pgVD69hHwbeToRD8uNaN1IrtAmiIj3f+tVnz1dhKCts+eRikX5EaW3jMWs6rGw5OEXfMGLJSQ9xa+hG9939S/L4d0gLi9yba5d5nlXxH4CT2btsIt8+nTJ05US66/bCZPZtBCwuYaq7XPfQI4tvYwZ+WfjGb6BZERChujVMlo7X+xpCAMOCE5cFcVQ1TGRO22a1o9V4MpI+4sICSd2IS2o9Syoa/vTBDNVLTPRcK613R4UOja8L6BZoGgz51WOVwUbuobfJS8nZ6AnIrFxTKHJyo4BcKQXZC5i5uW3WPOss5KF86TIPgjlnxClqEqFwPI/Kev74oxR9IpdYJZ7pGbOo59G0Y63Vok+oIcuwb5o5+POUTjhNRGj09sHi5oa7ier2dCmfep89aPIOPXtTKc6GMgYY/fW0QVawvKiuffow4mpaVNfU4sIxckHURBrZR/HJ+TqOfkLEFEUhNC0VgWRiZexsbniUSoDQmC2rAntyAFox4+aFp+alrWE2ZpPeCYokghTFbfIqvfX+h8EBoVvBVE9F9z77PniMtd8NDkD/umFIZKmOk4xnJTXrKexF/MSwowcZjXdLH4REhZ8+GQtk/2zvmnLhxEpNzMb51gDEkuDSMV5u9q8EwukIv+/oUPb/PUXmGAHXvpETBGTGDP31sh4aa/gwpG1bP84R8i53qde5loQ7ZFQIuG4/2lY9qlkUkln53xaMFT1YCLLxP6LKVPQmfULKicyvi/We5Y0MW7xvns+z1DoTz9pzZL/gqJwye+i0HRNKJY+BksXozwLUGegiw0OdN7cyGuNsamj8UMK9pEp2ICKE0wYbuJ1ubwA6+56v8wl6hHfsPabMLhGmyUM0C7xLfYqjwx/KPObbh6Q0vkyw4CHQysnnzB2nSd30BrKWWH1HvDm1X8opYE2IpF4HiIinMGBeeMBFFfhdDffjkcCw1FlZS1aqzj4o95r+DOuDdXwY24neiIn6spr317btXRFGbrqbk55aGl7tbrZVeZ
Content-Type: text/plain; charset="utf-8"
Content-ID: <197FD9B8ABD27D4D9598D7904DE125A4@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR08MB6826
Original-Authentication-Results: reliableenergyanalytics.com; dkim=none (message not signed) header.d=none;reliableenergyanalytics.com; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT064.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 8f99bbfb-f3db-4480-c00d-08d925c2c491
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: GCawwnCRqZvVxBuDnxCqTq04rLdvrPp4M4nlwABZTNihPSW838UjLobtPodBsvyNy6SQm6nXjkknlKVCSoSVmBIXLUaVx2K4FaNMWHJCBvEUyJ6ytZRdstUrkZEc1eA99G4jkWLKwKFjCLYZYUT8OpsoNLuWy2gLIjhGn8FL7K9KdH49kBrxOEXMHZKl8WP2bwBncKUeo3EXLv95SIRoon57wCSd10INcoa0mLkbeyXmIIHsvO3ly440UxSLL8+y22G8iCvVY5Qn2c8ATUALVEVqmuZ2/DrLm1Nlp4kRJKiwQKZP4IPcyzpOcLajb9GI/lwMyUxl1Yhknvpr85EjptYs0EJVvAi0n7mFESJ9U5pCG5e/wxwLNINSb5Ni7uNLCuyu+yHlXN5o7DDbnE2lPrLscv4BMuO6xjyMDXe45MLgC88pOAtOlorQIqN9Aib45xl5hdvnaGjc6GDtqeWOgndsBNebPbpIWAc0FLW9JpBJ4uTD4uSZL4v8Wo9ANv3RRvKwGU2ulTrhwDXXrOcSQOxlPWOmQmjL6VNinGtgbAcCQ8JrFMas3ZynhbFeU/lEAt+sR0MSXjsFeujT+KrSbEVM9w9uGCvC/EQImO7IiGhIyWSSOsPLuah14QEYDh2jT97BgK/POBrjfrozBSfXktZeCDqORKosb/KE67eqG+/Halfwk008Ni/mbvuF56ekwoPo5zyEIi8Td6kqjhoKrVSQDjeO1g1ozAK2ItH5Br8kN7A2nWe2/Y5smLcJ9ZtNeEBVc+Zny9aFyrbHFDOa7b3nnDlNz7dSqjNH/VeI4z5pDRxQniN2AoJJSbueXkU5
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(346002)(39850400004)(376002)(396003)(136003)(36840700001)(46966006)(2906002)(5660300002)(26005)(86362001)(70206006)(356005)(2616005)(316002)(36756003)(8676002)(6512007)(186003)(33656002)(336012)(81166007)(82740400003)(54906003)(66574015)(83380400001)(478600001)(36860700001)(6862004)(6486002)(53546011)(47076005)(966005)(70586007)(8936002)(4326008)(82310400003)(6506007); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Jun 2021 12:34:39.9502 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: d593d58d-ffb2-4476-5d6a-08d925c2ca72
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT064.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR08MB4036
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/zJELDWjuNp7mEaDry2E3lgs_aWo>
Subject: Re: [Suit] suit-firmware-encryption-00
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Jun 2021 12:34:52 -0000

Encryption support is not optional. It’s mandatory. Many organisations will not consent to their binaries being publicly available. This is easy to demonstrate: most MCUs support read-out protection. We can’t simply remove encrypted payload support because it changes the audit story. Instead, firmware authors must cooperate with auditors.

Best Regards,
Brendan

> On 31 May 2021, at 20:56, Dick Brooks <dick@reliableenergyanalytics.com> wrote:
>
> I believe encryption would "get in the way of" a malware scan performed
> during a software supply chain risk assessment.
>
>
> Thanks,
>
> Dick Brooks
>
> Never trust software, always verify and report! T
> http://www.reliableenergyanalytics.com
> Email: dick@reliableenergyanalytics.com
> Tel: +1 978-696-1788
>
> -----Original Message-----
> From: Suit <suit-bounces@ietf.org> On Behalf Of Hannes Tschofenig
> Sent: Monday, May 31, 2021 3:47 PM
> To: Michael Richardson <mcr+ietf@sandelman.ca>; Russ Housley
> <housley@vigilsec.com>; suit@ietf.org
> Subject: Re: [Suit] suit-firmware-encryption-00
>
> Hi Michael,
>
>>> SUIT is using signature for the authentication and integrity of the
>>> firmware.  If the signature remains in place, a party in the middle
> of
>>> the distribution cannot insert any malware.
>
>> The encryption of the firmware keeps third parties from auditing the
> software updates to determine if malware has been inserted at the "factory"
>> Both white and black hats are currently using binary diff systems to look
> at patches.  Black hats use this to develop exploits in the gap between 9am
> EST and 9am PST!
>> I am suggesting that this is a "Security Consideration"
>
> A description of the software is contained in the COSWID and, as Brendan
> suggests, in a MUD file that is included with the manifest (see
> https://datatracker.ietf.org/doc/html/draft-moran-suit-mud).
> Furthermore, I can imagine that those authorized to audit the software can
> do so either based on the source code or by giving them access to the
> binary.
>
> Ciao
> Hannes
>
> IMPORTANT NOTICE: The contents of this email and any attachments are
> confidential and may also be privileged. If you are not the intended
> recipient, please notify the sender immediately and do not disclose the
> contents to any other person, use it for any purpose, or store or copy the
> information in any medium. Thank you.
> _______________________________________________
> Suit mailing list
> Suit@ietf.org
> https://www.ietf.org/mailman/listinfo/suit
>
> _______________________________________________
> Suit mailing list
> Suit@ietf.org
> https://www.ietf.org/mailman/listinfo/suit

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.