<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Downgrading via Secure Buttonless DFU OTA</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/64094/downgrading-via-secure-buttonless-dfu-ota</link><description>Hi, We are looking for a way to downgrade our apps OTA. Currently, the only way we have found is by &amp;quot;lying&amp;quot; on package creation (ie- to downgrade fw3 to fw2, package fw2 as &amp;quot;4.0.0&amp;quot; via nrfutil). When reading about this, I have found the following flag</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 29 Jul 2020 09:17:38 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/64094/downgrading-via-secure-buttonless-dfu-ota" /><item><title>RE: Downgrading via Secure Buttonless DFU OTA</title><link>https://devzone.nordicsemi.com/thread/262147?ContentTypeID=1</link><pubDate>Wed, 29 Jul 2020 09:17:38 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:133791ac-18ab-4a70-8c73-019fc6e1e7f6</guid><dc:creator>Roiger</dc:creator><description>&lt;p&gt;Thanks for the great explanation Vidar!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Downgrading via Secure Buttonless DFU OTA</title><link>https://devzone.nordicsemi.com/thread/261929?ContentTypeID=1</link><pubDate>Tue, 28 Jul 2020 09:53:27 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3078e97f-c955-496f-8b25-3b9004b7de4e</guid><dc:creator>Vidar Berg</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Downgrade prevention is recommended for security reasons. Let&amp;#39;s say you issued have issued an update to your end-users with a security fix, then you would not want an attacker to be able to revert this by downgrading the FW.&lt;/p&gt;
&lt;p&gt;Without FW signing, you would not have a way to really prevent a downgrade anyway. The attacker could just create take an old update package and bump the version number (does not require access to a private key). So this makes the &lt;span&gt;NRF_DFU_APP_DOWNGRADE_PREVENTION&amp;nbsp; setting less relevant for non-signed updates&lt;/span&gt;. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Vidar&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>