‹ BackHN Continuity

Thread

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

220 points · 92 comments · synack

  1. stackghost · · focus · HN ↗
    > The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

    Not super practical, but neat attack

    1. stickfigure · · focus · HN ↗
      That is peanuts for a nation-state actor.
      1. stackghost · · focus · HN ↗
        Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.
        1. ssl-3 · · focus · HN ↗
          The RP2350 is an inexpensive microcontroller IC with reasonable performance and some very useful (and somewhat unusual) features in its PIO blocks.

          Why wouldn't a person build that into the heart of something important?

          1. sephamorr · · focus · HN ↗
            "Important" and "tamper proof against a determined adversary" are very different goals.
            1. jacquesm · · focus · HN ↗
              Tamper proof against a determined adversary starts at 'call us' not at '$10'.
          2. stackghost · · focus · HN ↗
            >Why wouldn't a person build that into the heart of something important?

            Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.

            1. rcxdude · · focus · HN ↗
              Rp2350s are advertised as having quite a few anti-tamper functions. They had a bounty when it launched to find similar vulnerabilities and they worked to patch the ones that were found. This is a lot more credible than a lot of advertised anti-tamper features.
              1. crote · · focus · HN ↗
                Not really. The RP2350 just adds some bog-standard security features the ESP32 family and plenty of others have had for ages, that's all.

                The goal of the bounty is to demonstrate that they aren't just a company making toys for hobbyists, and that they can be relied upon by the industry for basic IoT-level products. They are saying "it won't be completely trivial to extract your proprietary firmware", not "use this chip for your next HSM".

          3. alnwlsn · · focus · HN ↗
            Depending on what sort of important you're talking, those ICs don't have the usual "something important" environmental specs, like an extended temperature range, or certification for automotive use or safety critical applications, for one thing.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.