Post #3673805
2026-07-08 14:16 UTC
@kevinthomas@defcon.social honestly and truly there are only two things im taking issue with here, otherwise i think this is a cool project and i like it... these two things stick in my teeth and make me mad though:
one - you got buttmad at being asked to prove your claims re: crypto... dont do that. either say "i dont know how" or pay someone else to do it, or dont submit it to a crypto conference. requiring proof for claims on crypto is not academia being stupid, it is normal. abide by it or be seen in a poor light.
two - you claim this solution is superior to modern secure boot implementations and this is just absolutely false. you make claims about secure boot and denigrate the hardware root of trust when your solution itself is vulnerable to offline recovery in ways a modern secure boot enabled chip is not. in your github you disclaim this by sloughing responsibility off onto the users password, which is the only source of entropy in the system. modern secure boot is more robust than this, and not vulnerable to offline recovery in the same manner. my previous point bleeds into this one: you cant fucking prove any of this and you refuse to when asked - that inspires the opposite of confidence.
and finally, bonus stick: chipwhisperers do not cost $5 dude are you fucking kidding? $5 is such an enormous exaggeration its just wild.
Replies (1)
-
@kevinthomas@defcon.social 2026-07-08 14:19
@0x00string@infosec.exchange I did not get butt mad I answered the question asked. I appreciate you looking at the algorithm. Yes I was wrong about $5 I was referring to aftermarket but yes that was wrong of me. Anyway I hope the tool helps people on their own personal projects. Your point is fair.