<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bonding in DFU Bootloader</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/48171/bonding-in-dfu-bootloader</link><description>I have found many questions regarding passing bonding information from the application to the bootloader (e.g. https://devzone.nordicsemi.com/f/nordic-q-a/34497/dfu-with-bonds-and-nrf52810 ) and we already have Buttonless DFU working in several implementations</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 05 Jun 2019 12:55:00 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/48171/bonding-in-dfu-bootloader" /><item><title>RE: Bonding in DFU Bootloader</title><link>https://devzone.nordicsemi.com/thread/191118?ContentTypeID=1</link><pubDate>Wed, 05 Jun 2019 12:55:00 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:97c685f6-41aa-441a-a178-0debab6b4bb5</guid><dc:creator>ilnadi</dc:creator><description>&lt;p&gt;Thank you.&amp;nbsp; This will simplify the design.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bonding in DFU Bootloader</title><link>https://devzone.nordicsemi.com/thread/191084?ContentTypeID=1</link><pubDate>Wed, 05 Jun 2019 11:52:23 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:a3995f5c-b309-446d-82b3-6f3a2db99698</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I do not see any security improvements of having the bootloader support bonding. The data you are transferring is in any case available to &amp;quot;read&amp;quot; by various means (e.g. either by someone sniffing communication when bonding and/or by someone just get the hex by other means).&amp;nbsp;The best approach is to physically have a button the user must press to perform OTA, and then only when someone have physically access can they trigger OTA, you may still use signing of the hex file to ensure that only valid OTA will be performed.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;br /&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>