AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

SFT-8162: validate and confirm a developer pubkey before installing it

Public commit record

What the developer wrote

Authored by Jack

73/100 · Adequate
SFT-8162: validate and confirm a developer pubkey before installing it

The install flow checked only that the file was 88 bytes long, and showed
no screen for what was about to be trusted.

Add is_valid_firmware_pubkey(), which checks the 64 bytes are a reduced
point on secp256k1, and reject the file when they are not. The all zero
key fails that check, which is what this flow wants, since clearing the
slot goes through RemoveDevPubkeyFlow and its own confirmation.

Then show the key in the same form as View Developer PubKey and ask
before writing it. The card is also released before either screen rather
than held open across a prompt.

The C binding keeps accepting the all zero removal key and is unchanged.
The bootloader verifier is out of scope per the recorded decision on
SFT-7355.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a security gap in the Passport hardware wallet's developer-public-key installation flow. Previously, the device only checked that the key file was 88 bytes long and installed whatever 64-byte blob it found without showing it to the user. Now it verifies that the 64 bytes actually form a valid point on the secp256k1 cryptographic curve, and it shows the key on screen and asks for user confirmation before writing it to the secure element. The change prevents installing malformed or all-zero keys that could never verify a firmware signature, and it closes a social-engineering path where a user might blindly trust a malicious key file.

Recommended action

Treat this as a security-hardening fix and include it in the next firmware release. Review whether the C binding and bootloader verifier should also enforce the same validation, since the commit notes they are currently out of scope. Ensure the new unit tests run in CI.

Security signals we found

01

Input validation added for cryptographic public key before secure-element write

02

User confirmation prompt added before trusting a developer firmware signing key

03

All-zero key explicitly rejected in the install flow

04

Card slot lifecycle tightened: released before user prompt rather than held open

05

Unit tests added for validation function covering valid/invalid curve points and lengths

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.