rene_mobile’s avatarrene_mobile’s Twitter Archive—№ 8,236

    1. We (@insjku at @insjku) now run an external witness for multiple transparency logs, including the Pixel 6 firmware binary transparency log (latest checkpoint github.com/mhutchinson/mhutchinson-distributor/blob/main/distributor/logs/d0a1f19e973cd5cc3d4f26446ea418d33faefffb43ea1e3eadfe133287f71ff8/checkpoint.3) or the @FSecure Armory Drive (github.com/mhutchinson/mhutchinson-distributor/blob/main/distributor/logs/50dfc1866b26a18b65834743645f90737c331bc5e99b44100e5ca555c17821e3/checkpoint.3). Next step: signing key in secure HW.
  1. …in reply to @rene_mobile
    CC @AndreaBarisani with kudos for documenting the @FSecure log and firmware builds reproducibility particularly well.