Commit c9dccf6
committed
release: 7.14.2 security line — the device shows what it signs
Every defect closed here is the same shape: the device signed bytes it never
displayed, or displayed text it could not vouch for.
EVM
omitted chain_id no longer yields a pre-EIP-155 signature; it is refused
before any screen is drawn
arbitrary contract data requires AdvancedMode, and the check gates rather
than warns
0x clear-signing is bound to complete calldata and to both tokens resolving
calldata beyond the initial chunk is no longer described from hardcoded
ABI offsets
EIP-712
the structured JSON path is withdrawn: it could not guarantee that a
displayed value was the value being hashed, and one screen took its title
from the attacker-supplied domain name
EthereumSignTypedHash requires AdvancedMode and shows an explicit
blind-sign screen first
Display
message signing renders every byte, escaping non-printables, instead of
stopping at the first NUL
bodies too long for the screen are paged with n/m titles rather than
silently clipped
the fit measurement is draw_string()'s own walk with pixel writes off, so
measuring and drawing cannot disagree
Altcoins
THORChain and Maya memos keep their last character and refuse a declared
length that misdescribes its own content; trailing memo fields are disclosed
Osmosis prints the exact signed integer beside the exact denom
Cosmos IBC shows the receiver instead of printing the sender twice
Solana SPL amounts are scaled by the decimals in the signed instruction, and
never render a nonzero transfer as zero
Binance denom formatting no longer writes past its buffer
Setup and consent
an injected RecoveryDevice cannot write settings mid-ceremony
a cancelled passphrase confirmation is not cached
cancelled authenticator and Uniswap operations do not complete
Reproduced on signed v7.14.1 before the fixes and verified on 7.14.2 silicon
after them. CI now captures the OLED for these paths; it previously captured
none of them, because the harness read the firmware version with grep -oP,
which BusyBox lacks, and silently fell back to 7.14.0.
Not claimed: independent re-exploitation and a final adversarial round are
incomplete, and the fit measurement covers layout_standard_notification only,
so custom-layout address and xpub bodies still clip without warning.
deps/python-keepkey pins keepkey/python-keepkey#216, which merges once this is
green.1 parent 1af2ffe commit c9dccf6
100 files changed
Lines changed: 5362 additions & 803 deletions
File tree
- .github/workflows
- deps
- docs
- release
- rc30-evidence
- security
- include/keepkey
- board
- firmware
- lib
- board
- emulator
- firmware
- ethereum_contracts
- rand
- scripts
- build/docker
- device
- emulator
- emulator
- unittests
- board
- crypto
- firmware
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| |||
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
91 | | - | |
92 | | - | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
93 | 98 | | |
94 | 99 | | |
95 | 100 | | |
| |||
207 | 212 | | |
208 | 213 | | |
209 | 214 | | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
210 | 229 | | |
211 | 230 | | |
212 | 231 | | |
| |||
490 | 509 | | |
491 | 510 | | |
492 | 511 | | |
493 | | - | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
494 | 518 | | |
495 | 519 | | |
496 | 520 | | |
| |||
726 | 750 | | |
727 | 751 | | |
728 | 752 | | |
| 753 | + | |
| 754 | + | |
| 755 | + | |
| 756 | + | |
| 757 | + | |
| 758 | + | |
| 759 | + | |
| 760 | + | |
| 761 | + | |
| 762 | + | |
| 763 | + | |
| 764 | + | |
| 765 | + | |
| 766 | + | |
| 767 | + | |
| 768 | + | |
| 769 | + | |
| 770 | + | |
| 771 | + | |
| 772 | + | |
| 773 | + | |
| 774 | + | |
| 775 | + | |
| 776 | + | |
| 777 | + | |
| 778 | + | |
| 779 | + | |
| 780 | + | |
| 781 | + | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
| 787 | + | |
| 788 | + | |
| 789 | + | |
| 790 | + | |
| 791 | + | |
| 792 | + | |
| 793 | + | |
| 794 | + | |
| 795 | + | |
| 796 | + | |
| 797 | + | |
| 798 | + | |
| 799 | + | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
| 803 | + | |
| 804 | + | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
729 | 814 | | |
730 | 815 | | |
731 | 816 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| |||
92 | 92 | | |
93 | 93 | | |
94 | 94 | | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
95 | 103 | | |
96 | 104 | | |
97 | 105 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| |||
105 | 105 | | |
106 | 106 | | |
107 | 107 | | |
108 | | - | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
109 | 113 | | |
110 | 114 | | |
111 | 115 | | |
| |||
Submodule python-keepkey updated 16 files
- .github/workflows/copilot-review.yml+19
- keepkeylib/client.py+5-1
- scripts/generate-test-report.py+189
- tests/test_msg_display_disclosure.py+261
- tests/test_msg_ethereum_erc20_0x_signtx.py+11
- tests/test_msg_ethereum_signtx.py+101-21
- tests/test_msg_mayachain_signtx.py+3-3
- tests/test_msg_ping.py+41
- tests/test_msg_ripple_sign_tx.py+65
- tests/test_msg_thorchain_signtx.py+3-3
- tests/test_msg_ton_signtx.py+45
- tests/test_msg_tron_signtx.py+12
- tests/test_sign_typed_data.py+3
- tests/test_verify_typed_data.py+33
- tests/vectors/eip155_oracle.py+175
- tests/vectors/regenerate_eip155_vectors.py+64
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | | - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
7 | 12 | | |
8 | 13 | | |
9 | 14 | | |
| |||
0 commit comments