(08-09-2021, 09:51 AM)mouffa Wrote: the chips can have non user-flashable undisclosed binary blobs, so they can replace the same components with different blobs or factory-reprogram the chip, I would inspect the motherboard for the types of solder used etc
So since for once WE(pine64) are the customer can we request future hardware revs allow a checksum at power up? I think cryptographically signed firmware hash or something like that would serve the purpose.
Can we request that the no-dump fuses be left unblown?
How do you ID a fake IC in the wild without decapping the package?
How does a vendor verify authenticity of flashed firmware other than chain of custody or flashing in house and setting the no-flash fuses?
(edit)
If we are designing the board then including non-standard verification test points should be possible even if we have to plug in a serial line or something.