Definitely doable in a home lab for under $25k in equipment, likely under $10k.
Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).
BitBangingBytes 14 hours ago
Definitely doable in a home lab for under $25k in equipment, likely under $10k.
Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).
throwaway81523 12 hours ago
junofan 3 hours ago
Perhaps driven by restrictions on federal grants? https://media.api.sf.gov/documents/Briefing_Book_-_Muni_Fund...
Some cool tech. Wonder if we optioned the inductive charging system. https://www.gillig.com/buses/battery-electric/#1731934845437...
SV_BubbleTime 7 hours ago
byb 14 hours ago
There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.
octoberfranklin 12 hours ago
This is dismissive and glib. And it's the wrong lesson.
You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.
The "arms race" exists because the security model for trusted hardware is intrinsically flawed. If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race. So stop doing this! Trusted hardware also has extremely negative externalities on the whole computing ecosystem.
(*) or 45 years, if you exclude cryptosystems (56bit single-DES) used only because of silly export laws.
zephen 10 hours ago
As is your comment.
> And it's the wrong lesson.
It's only the wrong lesson if you believe that making it more difficult for governments to seize and decrypt their own citizens' mobile phones with impunity is not a valid goal.
> the security model for trusted hardware is intrinsically flawed.
It's only intrinsically flawed if you expect absolute perfection.
The fact that some math-based protections may be theoretically better than physical protections does not obviate the utility of physical protections, whether we are discussing computers or phones, or houses or cars.
It has been accepted since before any of us were born that there is no such thing as perfect physical security. Even your putative perfect cryptographic security still relies on the physical security of the plant holding the keys.
octoberfranklin 9 hours ago
zephen 8 hours ago
I have no idea how or why you would think I think this, since what I wrote was exactly the opposite of this, e.g. "It's only intrinsically flawed if you expect absolute perfection" and "It has been accepted since before any of us were born that there is no such thing as perfect physical security."
In any case, if you think that every piece of information that ordinary humans want to protect is worth it for nation-states to waste their million-dollar attacks on, we inhabit totally different realities.
And yet, there are many pieces of information that ordinary humans want to protect that many nation states would easily throw thousands of dollars at.
In other words, the fundamentals behind security are the same as it ever was.
vexed_vulpine 5 hours ago
For the average user these approaches make data loss MUCH more likely simply because you need a corporate IT department level of competency to consistently avoid data loss with them.
The glib exaggeration of this is that in not being permitted to manage and back up your own keys you actually create the situation where you have to hire someone to extract your keys for you and break into the device you own because of the failings of the technology!
mitxela 9 hours ago
rkagerer 3 hours ago
Does that mean there are four cores on the die? Is there crazy amounts of MUXing going on? Does the extra, semi-unused area give the chip a premium price tag? Or did I misinterpret this?
raphlinus 2 hours ago
jacquesm 15 hours ago
xattt 13 hours ago
jacquesm 13 hours ago
https://www.cs.uaf.edu/2007/fall/cs441/support/dram_sensor_1...
buescher 10 hours ago
nullc 3 hours ago
For one a similar instrument can be constructed from surplus parts for far less. Secondly, it's a single bit flip required. Now knowing the the technique works, a harness could be built that attempts it scattershot without the precise targeting and just has to try a lot of times. Using a different stimulus, e.g. xray it might well be possible without deencapsulating the part.
akoboldfrying 8 hours ago
I have a side question. I looked into the linked Raspberry Pi hacking challenge, and there's something very basic I couldn't figure out: It looks like the relevant script in the repo just writes 0xc0ff 0xffee a few times to the OTP as the "secret" to unlock. But given that $20000 was up for grabs, this can't possibly be the genuine secret being sought to claim the prize. (Indeed, I can't think of a secure way to install a secret from a public GitHub repo unless it involves running on-device code that encrypts something using some other, factory-installed secret key, which is just kicking the can down the road.) And given that the OTP on a brand new RP23550 is initialised to all zeros, it can't be that the genuine secret is programmed in at the factory either.
What am I missing? How does the genuine secret get installed on a person's RP2350?
striking 5 hours ago
akoboldfrying 3 hours ago
stackghost 16 hours ago
Not super practical, but neat attack
paulnpace 15 hours ago
*currently
stavros 15 hours ago
k12sosse 14 hours ago
TeMPOraL 14 hours ago
dist-epoch 14 hours ago
TeMPOraL 12 hours ago
I was referencing my own realization earlier today, when I was wondering if I can DYI a ground-penetrating radar to scan the allotment garden for hidden "surprises". A ground-penetrating radar is something I learned about as a kid watching a popular science videotape, back then a stupidly expensive high-tech piece of professional equipment.
But it hit me that there are two main forces keeping such technologies stupidly expensive and inaccessible to general public over time: costs of knowledge that went into their design (protected by patents and trade secrets), and specialized parts made in unique way or from unique materials, that don't happen to have alternate applications.
Nowadays, knowledge is not an issue - 20+ years is enough for all the relevant patents to expire, and information to have seeped through to the Internet, available in a combination of Wikipedia articles, textbooks, scientific papers, and blogs, plus we have good LLMs more than happy to synthesize that and transform into a DIY tutorial for dummies.
Which leaves the parts. Whether or not you can DIY such a tech really hinges on whether you can find the critical components somewhere. If they're still unique, you're paying $$$ for procurement (and it makes more sense to try and score broken/used equipment off eBay or something). But there's a chance there's a close equivalent that's part of mass consumer or prosumer device, at which point you just buy it and strip it for parts.
(Which way it is with ground-penetrating radars? Don't know, didn't bother to prompt an LLM with that question yet.)
MadnessASAP 10 hours ago
Where you will run into issues is processing radar signals into usable data. If you're happy with the results that radar was giving 30 years ago then it's fine and dandy, but the magic of modern radar is in the software, not the hardware.
jonathanlydall an hour ago
mitxela 9 hours ago
stavros 3 minutes ago
etdznots 4 minutes ago
_trampeltier 15 hours ago
mrlambchop 15 hours ago
stickfigure 15 hours ago
stackghost 14 hours ago
ssl-3 14 hours ago
Why wouldn't a person build that into the heart of something important?
sephamorr 14 hours ago
jacquesm 11 hours ago
stackghost 13 hours ago
Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.
rcxdude 13 hours ago
alnwlsn 12 hours ago
palmotea 14 hours ago
Is there anything about these techniques that are raspberry pi specific? It seems like they're using lasers to identify and flip particular bits in registers.
bob1029 14 hours ago
Some very high end HSMs must be actively powered at all times which makes disturbances in their local environments detectable at all times as well. Getting lucky and drilling through a part of the enclosure that isn't directly protected won't help you if a barometric pressure sensor is tripped as a consequence of breaking the hermetic seal.
palmotea 14 hours ago
That's interesting. I suppose if that technology is in use, the attack would have to occur in a pressure-controlled chamber, so breaking the seal wouldn't cause a change in pressure.
rcxdude 13 hours ago
overfeed 13 hours ago
pixl97 10 hours ago
Even a very sensitive pressure checker in a temp controlled sealed box would do it.
rcxdude 9 hours ago
MayeulC 13 hours ago
EvanAnderson 13 hours ago
Any path can be made into an optical path with a bright enough light. >smile<
stickfigure 13 hours ago
throwaway81523 12 hours ago
ironqcold 11 hours ago
throwaway81523 9 hours ago
bigiain 6 hours ago
yndoendo 12 hours ago
[0] https://simkl.com/tv/33956/chaos-communication-congress/seas...
[1] https://media.ccc.de/v/33c3-8127-how_do_i_crack_satellite_an...
bigiain 6 hours ago
TZubiri 15 hours ago
Rohansi 14 hours ago
Fred27 16 hours ago
orbital-decay 15 hours ago
junon 15 hours ago
mitxela 9 hours ago
bigiain 6 hours ago
I wouldn't want to be someone the NSA is "interested in".
I wouldn't even want to be someone that a customer of NSO Group is interested in. (Just ask Jamal Kashoggi's family or friends)
Hell, where I live they're about to give cops powers to let then hack your phone with a Cellebrite UFED at roadside stops. And it's not even just cops, fisheries enforcement officers Australia have been using UFEDs at least as far back as 2017 during illegal fishing investigations.
If you're doing things that might make someone rich or powerful enough unhappy, or someone in law enforcement - you pretty much need to stop using the internet. And the bar for "how powerful" your potential threat is keeps dropping lower and lower. Just look at all the stories about local cops abusing Flock cameras to stalk ex girlfriend or people critical of them, how could anyone possibly believe those same sort of cops aren't going to use roadside phone forced data extraction tools in exactly the same petty and personal ways, and with exactly the same lack of oversight and consequences?
mitxela 6 hours ago
bigiain 6 hours ago
brcmthrowaway 15 hours ago