top of page


When signing your update isn't enough: encrypting firmware updates
A signature decides whether a device accepts an update, not who can read it. Two ways to encrypt firmware updates, a shared product key or a key per device, where the plaintext and the keys exist, what one leaked key exposes, and what the CRA asks for.

Lauri Hokkanen
10 hours ago7 min read


What "signed update" really means
Secure boot decides what may run. A signed update decides what gets installed, and its security comes down to who holds the signing key, a second signature at boot, and anti-rollback. What the CRA expects, and three questions for your own product.

Lauri Hokkanen
Sep 254 min read
bottom of page
