From d72d8e83aa0d0abc228417dc9fa77c5bcbf724c9 Mon Sep 17 00:00:00 2001 From: Daniel Micay Date: Fri, 10 May 2019 16:41:39 -0400 Subject: [PATCH] note ID attestation will be optional --- static/install.html | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/static/install.html b/static/install.html index 5627bcc1..f46b67bd 100644 --- a/static/install.html +++ b/static/install.html @@ -139,9 +139,9 @@ TMPDIR="$PWD/tmp" ./flash-all.sh attestation root. Ideally, you should also do this before connecting the device to the network, so an attacker can't proxy to another device (which stops being possible after the initial verification). Further protection against proxying the initial - pairing will be provided in the future via support for ID attestation to include the - serial number in the hardware verified information to allow checking against the one - on the box / displayed in the bootloader. See the + pairing will be provided in the future via optional support for ID attestation to + include the serial number in the hardware verified information to allow checking + against the one on the box / displayed in the bootloader. See the Auditor tutorial for a guide.

After the initial verification, which results in pairing, performing verification against between the same Auditor and Auditee (as long as the app data hasn't been