‹ BackHN Continuity

Thread

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

220 points · 92 comments · synack

  1. byb · · focus · HN ↗
    The RP2350's secure enclave made it particularly attractive for use as a Yubikey alternative.

    There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.

    1. octoberfranklin · · focus · HN ↗
      There will always be an arms race between safe-crackers and safe-builders.

      This is dismissive and glib. And it's the wrong lesson.

      You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.

      The "arms race" exists because the security model for trusted hardware is intrinsically flawed. If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race. So stop doing this! Trusted hardware also has extremely negative externalities on the whole computing ecosystem.

      (*) or 45 years, if you exclude cryptosystems (56bit single-DES) used only because of silly export laws.

      1. ImPostingOnHN · · focus · HN ↗
        >> There will always be an arms race between safe-crackers and safe-builders.

        > You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.

        AES encrypted ciphertexts are not a safe. A safe is a physical object.

        > If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race.

        That's what we're discussing, yes: a scenario in which physical access to a safe is already acquired. Given that context, don't you think changing the topic to 'non-safes' and 'avoiding physical access' is a little dismissive and glib?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.