Straits Taylor Rule:
i = r* + π* + 1.5(π−π*) + 0.5(y−y*) + α(SOH−SOH*) + β(BEM−BEM*), α,β > 0
Let’s see if a hike could open SOH or produce a single barrel :)
You can’t 25bp a chokepoint and r* isn’t neutral. It’s SOH risk premium, and We set it.
Stay unanchored !
@gridplus hypothetically if someone forces you to sign a fw, what is the best way for us to know and how can we protect/mitigate ourselves? any tips are much appreciated
@KeystoneWallet thanks for writing this thread. For cold boot attacks, I am curious why we don't erase the RAM on every switch-off instead of waiting for sudden temperature drops?
@androolloyd@DZack23@gridplus@danrobinson thanks for your explanation. Somehow the CT give me a vibe that all HWW can do 2. Is gridplus the only one that cannot do 2? i.e. giving any blackhats the fw signing key to authentically upgrade gridplus devices, can they do full extraction?
@gridplus@DZack23@danrobinson is the device designed in a way that I only need to trust the secure enclave and that it never gives you or your firmware the keys? or do I still need to trust you somehow somewhere?
@DZack23@gridplus@danrobinson can I clarify the "handles" with these two worst case scenarios:
1/ fw asks the Secure Element to sign (potential malicious) txs - it's never ever able to get the keys from SE.
2/ fw can technically ask the Secure Element to give the keys.
I am fine with 1 but not 2.
@evan_van_ness@one_chosun does it still requirement the same trust assumptions though? It is closed source and a malicious firmware update could leak keys.