<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Can a third-party attacker extract public key?</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/23920/can-a-third-party-attacker-extract-public-key</link><description>Can a third-party attacker extract the public key in the signed firmware(.zip) generated by nrfutil through decompile hex or bin file?</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Sun, 30 Jul 2017 22:32:52 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/23920/can-a-third-party-attacker-extract-public-key" /><item><title>RE: Can a third-party attacker extract public key?</title><link>https://devzone.nordicsemi.com/thread/94143?ContentTypeID=1</link><pubDate>Sun, 30 Jul 2017 22:32:52 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4f89cec6-e770-4cf5-96fe-a8eeb9fa4d59</guid><dc:creator>Roger Clark</dc:creator><description>&lt;p&gt;You&amp;#39;re welcome&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can a third-party attacker extract public key?</title><link>https://devzone.nordicsemi.com/thread/94142?ContentTypeID=1</link><pubDate>Sun, 30 Jul 2017 09:04:50 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:d96ed8bd-7cf4-4430-9955-548f5e198625</guid><dc:creator>J.Kwon</dc:creator><description>&lt;p&gt;Thank you.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can a third-party attacker extract public key?</title><link>https://devzone.nordicsemi.com/thread/94141?ContentTypeID=1</link><pubDate>Sun, 30 Jul 2017 08:38:16 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:46b05669-db31-4a43-b3db-447059214caf</guid><dc:creator>Roger Clark</dc:creator><description>&lt;p&gt;AFIK.&lt;/p&gt;
&lt;p&gt;The firmware (binary) is signed but not encrypted by nrfutil&lt;/p&gt;
&lt;p&gt;Hence they public key can be extracted.&lt;/p&gt;
&lt;p&gt;However Nordic uses public key encryption, so that even if the public key is discovered, its not possible to create signed firmware unless you know the Private key -&lt;/p&gt;
&lt;p&gt;If you want you firmware binary to be encrypted so that it can be reverse engineered, you&amp;#39;ll need to encrypt the firmware and use a bootloader that decrypts as well as just checking that signature.&lt;/p&gt;
&lt;p&gt;@RK. You pipped me to the post.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can a third-party attacker extract public key?</title><link>https://devzone.nordicsemi.com/thread/94140?ContentTypeID=1</link><pubDate>Sun, 30 Jul 2017 08:35:59 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e3a788f7-36e7-45cf-a74d-2de7e803ab2b</guid><dc:creator>RK</dc:creator><description>&lt;p&gt;who cares if they could extract a public key, the whole point of a public key is that .. it&amp;#39;s public.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>