Differential photon-emission microscopy localized debug enable register activity and narrowed the laser search before SWD-guided injection set the two bits required to restore Secure debug on an RP2350 A4.
92 comments
Definitely doable in a home lab for under $25k in equipment, likely under $10k.
Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).
Perhaps driven by restrictions on federal grants? https://media.api.sf.gov/documents/Briefing_Book_-_Muni_Fund...
Some cool tech. Wonder if we optioned the inductive charging system. https://www.gillig.com/buses/battery-electric/#1731934845437...
Don’t let fancy language like lock-step dissuade you from trying. The people who configured that chip also have to have done their job perfectly or it might still have a way in!
There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.
This is dismissive and glib. And it's the wrong lesson.
You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.
The "arms race" exists because the security model for trusted hardware is intrinsically flawed. If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race. So stop doing this! Trusted hardware also has extremely negative externalities on the whole computing ecosystem.
(*) or 45 years, if you exclude cryptosystems (56bit single-DES) used only because of silly export laws.
For the average user these approaches make data loss MUCH more likely simply because you need a corporate IT department level of competency to consistently avoid data loss with them.
The glib exaggeration of this is that in not being permitted to manage and back up your own keys you actually create the situation where you have to hire someone to extract your keys for you and break into the device you own because of the failings of the technology!
As is your comment.
> And it's the wrong lesson.
It's only the wrong lesson if you believe that making it more difficult for governments to seize and decrypt their own citizens' mobile phones with impunity is not a valid goal.
> the security model for trusted hardware is intrinsically flawed.
It's only intrinsically flawed if you expect absolute perfection.
The fact that some math-based protections may be theoretically better than physical protections does not obviate the utility of physical protections, whether we are discussing computers or phones, or houses or cars.
It has been accepted since before any of us were born that there is no such thing as perfect physical security. Even your putative perfect cryptographic security still relies on the physical security of the plant holding the keys.
> You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.
AES encrypted ciphertexts are not a safe. A safe is a physical object.
> If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race.
That's what we're discussing, yes: a scenario in which physical access to a safe is already acquired. Given that context, don't you think changing the topic to 'non-safes' and 'avoiding physical access' is a little dismissive and glib?
I have a side question. I looked into the linked Raspberry Pi hacking challenge, and there's something very basic I couldn't figure out: It looks like the relevant script in the repo just writes 0xc0ff 0xffee a few times to the OTP as the "secret" to unlock. But given that $20000 was up for grabs, this can't possibly be the genuine secret being sought to claim the prize. (Indeed, I can't think of a secure way to install a secret from a public GitHub repo unless it involves running on-device code that encrypts something using some other, factory-installed secret key, which is just kicking the can down the road.) And given that the OTP on a brand new RP23550 is initialised to all zeros, it can't be that the genuine secret is programmed in at the factory either.
What am I missing? How does the genuine secret get installed on a person's RP2350?
For one a similar instrument can be constructed from surplus parts for far less. Secondly, it's a single bit flip required. Now knowing the the technique works, a harness could be built that attempts it scattershot without the precise targeting and just has to try a lot of times. Using a different stimulus, e.g. xray it might well be possible without deencapsulating the part.
https://www.cs.uaf.edu/2007/fall/cs441/support/dram_sensor_1...
Read the full thread on Hacker News →
Related stories
- Laser Your Way into Debug Mode on the RP2350hackaday.comHacker News · 4 points · 11 days ago
- Lobsters · 2 points · over 7 years ago
- DEV Community · 27 points · 4 days ago
- Planetary Boundaries Laser Talk Bookletdocs.google.comHacker News · 1 points · 10 days ago
- China's 6th-Gen J-36 Fighter-Bomber to Feature Combat Laseren.defence-ua.comHacker News · 6 points · 10 days ago
- Hacker News · 1 points · 11 days ago