Create article about updates
I'm not sure if this should be a separate page or if it should be in Foris/Updater documentation.
There should be a reference to all supported ways of SW update (updater via cli/foris, medkit via usb/network)
There should be a reference about used encryption in medkit signature and in packages installed by the updater. We should also describe the properties of repo.turris.cz TLS certificate.
There should be a reference to updater documentation which describes its security consideration (example "Goals to protect against specific attacks" https://github.com/theupdateframework/specification/blob/master/tuf-spec.md#the-update-framework-specification)
This should help meet the following mandatory requirements for Tier 1 defined by CSA Singapore's Cybersecurity Labeling Scheme
- 5.3-2: When the device is not a constrained device, it shall have an update mechanism for the secure installation of updates.
- 5.3-3: An update shall be simple for the user to apply.
- 5.3-7: The device shall use best practice cryptography to facilitate secure update mechanisms.
- 5.3-8: Security updates shall be timely.
- 5.3-10: Where updates are delivered over a network interface, the device shall verify the authenticity and integrity of each update via a trust relationship.
Related to https://gitlab.nic.cz/turris/biz/singapore-certification/-/issues/1