‹ BackHN Continuity

Thread

Original Sony PlayStation 2 security chip 'broken wide open' after 26 years

285 points · 91 comments · rbanffy

  1. ethagnawl · · focus · HN ↗
    > Some of the reverse engineering tricks utilized by DiscoStarslayer include chemically decapping the CXP102064 to expose the die, then using microscopes and optical dumping skills to analyze the silicon chip circuitry. In this case, a lucky break during the hacking apparently uncovered an exploit that provided a method whereby the chip’s data could be extracted through software.

    This is next level commitment to the cause.

    Also, I can totally imagine their reaction when they discovered the exploit and realized they could put down the ... chemicals. XD

    1. spicyjpeg · · focus · HN ↗
      There actually is a pretty large community of hardware reverse engineers decapping chips for fun, sometimes just to dump internal ROMs (like in this case) and other times going as far as to try reconstructing the original schematics and netlists in order to document the chip's internals and allow for more accurate emulation, in some cases all the way down to the transistor level [1] [2]. If you want to learn more, Ken Shirriff has written a lot of blog posts on the subject [3] and Siliconprawn [4] hosts a huge collection of die shots from many contributors.

      [1] <a href="https:&#x2F;&#x2F;floooh.github.io&#x2F;visual6502remix" rel="nofollow">https:&#x2F;&#x2F;floooh.github.io&#x2F;visual6502remix

      [2] <a href="https:&#x2F;&#x2F;github.com&#x2F;iaddis&#x2F;metalnes" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;iaddis&#x2F;metalnes

      [3] <a href="https:&#x2F;&#x2F;www.righto.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.righto.com&#x2F;

      [4] <a href="https:&#x2F;&#x2F;siliconprawn.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;siliconprawn.org&#x2F;

      1. darkfloo · · focus · HN ↗
        Doesn’t decapping chips require hydrofluoric acid ? If so I cannot express enough respect, the one person I’ve interacted with that regularly worked with it put the fear of god with by showing what one insignificant miss for anything else did to his finger
        1. monocasa · · focus · HN ↗
          No, the default acid used is nitric acid. Which should definitely be treated with respect, but isn&#x27;t nearly as nasty as anything with fluorine.

          But if you have a few examples of the chip and can break a few eggs to make an omelette, there are techniques that just involve hitting the epoxy with a blow torch and&#x2F;or opening it up with plyers.

          1. joshumax · · focus · HN ↗
            Not just regular nitric acid either, but red&#x2F;white fuming nitric acid in many cases!

            Back during my teenage years I used to make the stuff for decapping projects and amateur rocketry by grabbing the ingredients from our local hardware store and distilling it in a make-your-own-moonshine kit I bought off of craigslist.

            Worked great up until the police were called because the store employees thought I was making bombs. I hear heating up sulfuric acid is the better way to decap epoxy chips nowadays.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.