‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. gmueckl · · focus · HN ↗
    Apple has to allownpost-manufacruring exchanges of camera due ton right of repair legislation. This requires them to publish pairing tools that are to be used during the repair process to update all the cryptographic vérification chains in the device.

    Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.