There could be multiple levels of UB certification ranging from : only keys to fully open sourcing the firmware upon termination
There could be multiple levels of UB certification ranging from : only keys to fully open sourcing the firmware upon termination
i'm new to this but we do want to demonstrate sincerity and put our $ where our mouth is.
Escrow triggered by insolvency or product termination would substantially improve on the status quo.
Otherwise, imagine this scenario:
Company release a product and pushes out the version for the certification. Updates require new versions to be signed with a particular key. A couple months later, the key is leaked! Okay, so keys are rotated and a new update is pushed and the old key is blocked.
What happens to the certification? What use is the certified key? What use is the certified source code? The certification should mandate a user-activatable factory-reset to the certified keys and code, which can't be tampered with by firmware to block or modify a different firmware from being installed.