pip install --no-cache-dir ledgerblue
python -m ledgerblue.checkGenuine --targetId 0x33100004
The source code is available here.
Application verification
When opening an application, a Non Genuine warning is displayed if the app has not been
signed by Ledger. A modified User Interface (as found in
https://github.com/LedgerHQ/nanos-ui) will also display a warning message on boot.
Root of trust
The root of trust for the current batch is the following secp256k1 public key:
0490f5c9d15a0134bb019d2afd0bf2971497384597
06e7ac5be4abc350a1f818057224fce12ec9a65de18ec34
d6e8c24db927835ea1692b14c32e9836a75dad609
- as checked here Genuine.py