GPL v3
GPL v3
Posted Aug 9, 2012 19:26 UTC (Thu) by iabervon (subscriber, #722)In reply to: GPL v3 by Richard_J_Neill
Parent article: GENIVI: moving an industry to open source
I think that the right thing, from the point of view of allocating responsibility, would be to check at boot that the image is signed by a key stored in a PROM (or ROM) in a ZIF socket inside the dashboard. If you want to change your firmware, you have to change the PROM to hold a key you have the private part to, and sign your new firmware. Then, if the system malfunctions in an unsafe way, it'll point to you as the responsible party. More generally, if the owner of the vehicle wants to install a Bose IVI system in a Ford car, they can do this with no more hassles that it used to be to put in a custom stereo, but they're also clearly shifting the safety responsibility to Bose from Ford, removing the chip that says "Ford IVI" and putting in the one from the Bose box. (While they're at it, use JTAG to install firmware images, to make the sort of equipment needed to install new firmware at all comparable to the sort of equipment needed to install a different public key.)