With this it might be easier to just “gift” someone the latest iPhone on which you installed an hardware exploit.
With this it might be easier to just “gift” someone the latest iPhone on which you installed an hardware exploit.
Traditionally this has been physical possession of the device.
The treacherous computing model is to make the trust root a key that only the manufacturer has.
I'm proposing that the trust root should be "possession of the device for X days", which doesn't privilege the manufacturer with indefinite control over something they've supposedly sold.
I don't understand what you're describing. Things like "2FA" and "notifications" aren't part of a bootloader, and therefore would have to be implemented externally. Keeping the manufacturer as part of the privileged base is still the dark ages.
FWIW the answer to the gifted trojan iPhone is to make the bootloader report the signing key that it is trusting. If you receive an iPhone from someone else and you want to assure integrity, you either plug it into another device of yours which checks the Apple signing key (possibly needing to wait X days to load it), or you bring the device to an Apple store where they do it for you.
Some fallback to possession of a device for a time fallback would be good to avoid needless e-waste though. It's pretty ridiculous to have a perfectly good item that you can't actually use because it got software bricked.
There’s something wrong with that model.
But sure, go ahead and design a different system where say the device's current key can be used to replace itself with a new key - the important part is that there are no permanent privileged keys that cannot be changed by the owner. But then you have to mandate that this procedure is carried out when a device is sold, otherwise it's not really a sale.
Such schemes seem likely to have pitfalls for losing or corrupting the key though, and I'm personally more comfortable with falling back on physical reality which we've learned how to deal with over thousands of years rather than ending up with perfectly good devices that cannot be used.