pico-quorum

Threat model: a Trust M PicoQuorum signer as one owner of a Safe

Written for the other owners. It says what you can rely on, what you can’t, and what you can check yourself.

What the device is

What you can rely on

The key never leaves the chip.

The device shows what it signs.

One owner, not the Safe. Losing or compromising the device costs one signature out of the three needed. The other owners can execute without it and rotate it out.

You can check the chip yourself.

What you can’t rely on

Whoever holds the device can make it sign anything.

A Trust M keeps no record of its signatures.

What the binding proves.

What the bundle reports.

The firmware is the operator’s.

The transaction service.

Infineon’s own objects before T9. On a chip that has not been through T9, the factory key’s rules can be rewritten by anyone on the chip’s bus, and the factory key replaced (shown on a test chip). That can’t touch the Safe key or fake Infineon’s certificate. It can only break the chip’s proof of being genuine. T9 freezes those objects too, and tools/quorum verify now checks that the factory key still answers a fresh challenge (live:) and still has Infineon’s rules.

The chip generation. TM1 looks like a first-generation Trust M (Infineon CA 101, firmware build 0809). This has not been confirmed from Infineon’s documents. The later generation’s authorization features, which a PIN would need, may not be there.

The breakout. Adafruit 4351 is an evaluation board. The secure element resists physical attack. The board, the I2C wires and the Pico do not.

What follows

Not for a key whose single compromise loses funds. It is one owner among several, and the others should be different kinds of device in different hands (CONFIGURATION.md).

Treat it like a hardware wallet that has no PIN:

Before you sign anything the Pico also signed, check what you are signing on your own device, as you would anyway. A Pico confirmation means “the operator looked at this on the Pico”. It does not mean “this is safe”.