Fun with firmware file formats and fingerprints

This page summarizes the projects mentioned and recommended in the original post on /r/TREZOR

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • data

    :package: Data files for Trezor (by trezor)

  • Now, on to fingerprints. All the firmware update logic is driven by a file called releases.json (trezor-one version). This file was last updated in commit #d4aaa1b signed with GPG key 4AEE18F83AFDEB23 belonging to @vdovhanych. In this file is a 256bit checksum called fingerprint. Now through the git GPG signature we can verify the authenticity of this file, and through the fingerprint we can verify the authenticity of the firmware.

  • trezor-firmware

    :lock: Trezor Firmware Monorepo

  • Now with the help of curl, tail, dd, openssl and xxd we should be happy that nothing fishy is happening with the firmware verification. If we are less skeptical, obviously the trezorctl firmware verify command will do all this for us. And if you want even more verbosity the headertool.py script will do all of this, and then some. One really nice feature is the "critical bugfix" flag to know when updates are really manditory.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • ¿How to start in bitcoin?

    1 project | /r/Bitcoin | 17 Oct 2023
  • Trezor unveils Trezor Safe family of devices

    1 project | news.ycombinator.com | 12 Oct 2023
  • New to the Crypto? 10 tips I wish I knew when entering the space

    1 project | /r/GGCrypto | 19 Sep 2023
  • Trezor developer confirms private keys can be extracted if firmware is corrupt

    1 project | /r/CryptoCurrency | 8 Jul 2023
  • Trezor model 1 not recognized

    2 projects | /r/TREZOR | 22 Jun 2023