‹ BackHN Continuity

Thread

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

220 points · 92 comments · synack

  1. BitBangingBytes · · focus · HN ↗
    I appreciate all the details they provide in the post. The $250k in lab gear is useful when initially discovering, exploiting and documenting attacks like this.

    Definitely doable in a home lab for under $25k in equipment, likely under $10k.

    Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).

    <a href="https:&#x2F;&#x2F;youtu.be&#x2F;URmI1VVilek" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;URmI1VVilek

    1. SV_BubbleTime · · focus · HN ↗
      I have an application on an SPC58 that I really want to know more about. But unfortunately; it’s a dual core with lockstep. So if it could be done; I think that automatically double-pluses the budget.
      1. BitBangingBytes · · focus · HN ↗
        Don’t need lasers for that chip, it absolutely can be done with enough time and effort.

        Don’t let fancy language like lock-step dissuade you from trying. The people who configured that chip also have to have done their job perfectly or it might still have a way in!

        1. SV_BubbleTime · · focus · HN ↗
          It’s two power supplies, two cores, lockstep, and an HSM they hype up… I’m pretty sure I would need two emps and a high precision rig at the minimum.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.