Skip to content

fwTPM: Dictionary Attack (DA) hardening and DA/noDA test coverage#541

Merged
dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:fwtpm-da-hardening
Jun 25, 2026
Merged

fwTPM: Dictionary Attack (DA) hardening and DA/noDA test coverage#541
dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:fwtpm-da-hardening

Conversation

@aidangarske

@aidangarske aidangarske commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

ZD 22030

dgarske
dgarske previously approved these changes Jun 25, 2026

@dgarske dgarske left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skoll Multi-Scan Review

Modes: review-securityOverall recommendation: APPROVE
Findings: 2 total — 2 posted, 0 skipped
2 finding(s) posted as inline comments (see file-level comments below)

One or more scans did not complete — the results below are partial.

Posted findings

  • [Low] [review-security] lockoutAuth recovery timer restarts on every Startup, so clocked builds measure per-boot uptime rather than elapsed wall-clocksrc/fwtpm/fwtpm_command.c:695-704
  • [Info] [review-security] Failed-auth path persists FLAGS to NV on every failure (flash wear / NV-bound auth latency)src/fwtpm/fwtpm_command.c:15903-15916

Review generated by Skoll

Comment thread src/fwtpm/fwtpm_command.c
Comment thread src/fwtpm/fwtpm_command.c
@dgarske dgarske assigned wolfSSL-Bot and unassigned dgarske Jun 25, 2026
@dgarske dgarske merged commit 1601a78 into wolfSSL:master Jun 25, 2026
196 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants