logoalt Hacker News

lowbloodsugartoday at 5:55 AM0 repliesview on HN

> Elgato signs the firmware updates with Ed25519 over a SHA-512 hash of the firmware payload, and rejects firmware that doesn’t validate.

Oh very good!

> This means that a single HTTP POST of ATSE=0200ED94,0E001009 turns the signature check into a no-op, and we can freely update to a firmware image without a legitimate signature.

Oh that was going so well. Just wow.