‹ BackHN Continuity

Thread

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

220 points · 92 comments · synack

  1. stackghost · · focus · HN ↗
    > The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

    Not super practical, but neat attack

    1. stickfigure · · focus · HN ↗
      That is peanuts for a nation-state actor.
      1. stackghost · · focus · HN ↗
        Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.
        1. ssl-3 · · focus · HN ↗
          The RP2350 is an inexpensive microcontroller IC with reasonable performance and some very useful (and somewhat unusual) features in its PIO blocks.

          Why wouldn't a person build that into the heart of something important?

          1. stackghost · · focus · HN ↗
            >Why wouldn't a person build that into the heart of something important?

            Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.

            1. rcxdude · · focus · HN ↗
              Rp2350s are advertised as having quite a few anti-tamper functions. They had a bounty when it launched to find similar vulnerabilities and they worked to patch the ones that were found. This is a lot more credible than a lot of advertised anti-tamper features.
              1. crote · · focus · HN ↗
                Not really. The RP2350 just adds some bog-standard security features the ESP32 family and plenty of others have had for ages, that's all.

                The goal of the bounty is to demonstrate that they aren't just a company making toys for hobbyists, and that they can be relied upon by the industry for basic IoT-level products. They are saying "it won't be completely trivial to extract your proprietary firmware", not "use this chip for your next HSM".

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.