Skip to content

Please provide documentation on how to verify firmware and bootloader #17

@Giszmo

Description

@Giszmo

https://onekey.so/en-US/hardware claims the firmware and bootloader are Open Source yet nowhere in the (English) documentation can I find how to verify or at least obtain the firmware binary. Furthermore the linked repository is just a text document, not mentioning "firmware", so I'm not even sure this repo is correct for this issue.

For the purpose of WalletScrutiny's review of your wallet I will have to conclude the hardware wallet uses closed source due to the missing link from the product's page to this or any other repository containing firmware source code.

Please update your product website to

  • link to the correct firmware and bootloader repositories
  • link to the signed binaries for every release
  • document how the hardware wallet asks the user for approval, at least optionally showing the binary's hash, so the user can make sure he's installing what he wants to install

As this repository here is a fork of Trezor's firmware, I assume this is merely a documentation issue and hope to soon be able to feature your product as reproducible just like the Trezor One.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions