(no title)
currywurst | 9 years ago
In case the Mender folks are here, have you looked into incorporating the concerns addressed bt The Update Framework (TUF) https://theupdateframework.github.io/
currywurst | 9 years ago
In case the Mender folks are here, have you looked into incorporating the concerns addressed bt The Update Framework (TUF) https://theupdateframework.github.io/
eystein|9 years ago
Yes, we have looked into it and the nice thing is that TUF seems to be quite easy to add as an additional security layer down the road.
One interesting challenge is downgrade attacks. How do you allow rollback of a bad deployment while disallowing an attacker to deploy an old and vulnerable version?
theamk|9 years ago
aseipp|9 years ago