Thank you for the detailed information.
Checking on my several LKs showed that all have firmware 0.10, as you rightly pointed out.
Checking on my two NitroKey Pro 2, both are 0.15 (they were purchased much later)
It appears to be the latest and final firmware release, since dev has stopped and the product is being discontinued anyway.
I wonder how many LKs Purism still have in stock - and should they all be considered obsolete?
Those LibremKeys will never be updated, even if Purism rebases on firmware 0.15 and comes up with a firmware update. The reason for this is that firmware 0.10 and below CANNOT be updated with nitropy cli: it lacks a bootloader needed for flashing the new firmware once the device gets enabled in firmware flashing mode. Unfortunately, this bootloader (and the possibility to update the firmware via cli) appeared as a new feature of version 0.11 - one version above LKs!
But is this really so bad? There has been a lot of talk and divergent opinions on the subject of there security dongles and firmware upgradability. For some threat model, this is viewed as an unacceptable liability and a considerable increase of the attack surface: there should be no way to tamper with the device by simply reflashing a forged or modified firmware.
On the contrary, some claim that firmware updates are necessary for correcting bugs or flaws; and also as a way to introduce new features on the same product (which is what Nitrokey has done from firmware versions 0.11 and above)
I don’t know…
Which is best? I guess it depends on the threat model, in the end.
1 Like