Skip to content

Cryptographically sign firmware downloads + publish hashes #17

@generalmanager

Description

@generalmanager

To improve security of the upgrade path and simultaneously protect against corrupted downloads, please publish secure hashes of the firmware files. Specifically SHA256 and/or SHA512.

In addition it'd be great if you'd actually cryptographically sign your releases, e.g. with GPG so users can make sure they aren't uploading a compromised firmware to the charger, which often has priviliged network access as most users won't be able to jail it into a separate VLAN.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions