AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 62 Bitcoin

Merge pull request #700 from Foundation-Devices/SFT-8162-dev-pubkey-confirm

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #700 from Foundation-Devices/SFT-8162-dev-pubkey-confirm

SFT-8162: validate and confirm a developer pubkey before installing it
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit hardens the way Passport hardware wallets install a 'developer public key' used to authorize custom firmware. Previously, any 64-byte blob read from a microSD card could be written straight into the secure element. Now the device checks that the blob is a mathematically valid point on the Bitcoin curve (secp256k1) and shows the user a confirmation screen before storing it. The change prevents installing a malformed or all-zero key that could never verify firmware signatures, and it adds a user approval step so a key cannot be silently swapped.

Recommended action

Treat as a security hardening fix and include in release notes. Users running developer firmware should update so that only valid developer pubkeys can be enrolled, and so that enrollment requires explicit on-device confirmation. No immediate emergency response is indicated because the feature requires physical microSD access and developer mode, but the fix closes a meaningful trust-boundary weakness.

Security signals we found

01

Input validation added for public-key material before secure-element write

02

User confirmation screen added before trusting a developer pubkey

03

Malformed / all-zero / out-of-range public keys are now rejected

04

Unit tests added for validation function

05

Developer-mode feature (custom firmware authorization) is the affected surface

Risk score

Why this scored 62/100

Our methodology →
Potential impact 18/30
Exploitability 14/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.