Issue dossier

The later public CDC Badge OS README states that flashing can wipe stored FIDO2/U2F credentials, TOTP seeds, password-vault entries, GPG keys, and PIN data; it calls the project a proof of concept/demonstrator and says not to use it as-is for production or security-critical deployments.

A linkable camp-impact record with badge context, severity, evidence confidence, and source notes.

Back to issues index

beta firmware, sensitive-data, and security-critical-use boundary · public firmware README · public source explicitly pre-1.0 beta

The record may describe the public software capability surface but does not endorse the firmware, vouch for its cryptography, privacy, data durability, or safety, or imply it was the software deployed at 39C3.

Badge
39C3 Critical Decentralization Cluster Badge
Category
beta firmware, sensitive-data, and security-critical-use boundary
Severity
warning
Confidence
public firmware README
Status
public source explicitly pre-1.0 beta
Timeframe
2026 public firmware state
Source note
krim404/cdc-badge-os README.

Evidence

Related Resources

Source trail

Evidence Sources

Critical Decentralization Cluster · retrieved 2026-05-15

39C3

Cluster-owned retrospective for the completed 39C3 assembly, its dates and location, and its direct CDC Badge repository link.

Badge: 39C3 Critical Decentralization Cluster Badge