There is only a catch-22 if we need _that time source_ to verify its time.
That's not how things work, though: we have hundreds available, so there is no catch-22 whatsoever: we check multiple sources and go with the majority vote, then flag an error for any outlier(s).
If your wifi connection is MITMed, your adversary could MITM all the connections, even if you make hundreds.
If you have trouble imagining a user taking their wifi lightbulb to a coffee shop, imagine instead you're a device vendor and a customer is trying to MITM their own device to embarrass you in a Defcon presentation...
Sure, but now you've turned it from "You can't trust network time" into "you can't trust your wifi" and while 100% correct: now you're commenting on a different article altogether.
Comments
There is only a catch-22 if we need _that time source_ to verify its time.
That's not how things work, though: we have hundreds available, so there is no catch-22 whatsoever: we check multiple sources and go with the majority vote, then flag an error for any outlier(s).
If your wifi connection is MITMed, your adversary could MITM all the connections, even if you make hundreds.
If you have trouble imagining a user taking their wifi lightbulb to a coffee shop, imagine instead you're a device vendor and a customer is trying to MITM their own device to embarrass you in a Defcon presentation...
Sure, but now you've turned it from "You can't trust network time" into "you can't trust your wifi" and while 100% correct: now you're commenting on a different article altogether.
How do you know that it’s not the majority of your sources that has been mitm’ed?
Not all of these sources come through the Internet. Think GPS, GSM, radio time signals (DCF-77 or the likes).
Those solutions all require additional hardware - hardware that's far more expensive than an on-board real-time clock and battery.