‹ BackHN Continuity

Thread

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

220 points · 92 comments · synack

  1. stackghost · · focus · HN ↗
    > The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

    Not super practical, but neat attack

    1. stickfigure · · focus · HN ↗
      That is peanuts for a nation-state actor.
      1. stackghost · · focus · HN ↗
        Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.
        1. palmotea · · focus · HN ↗
          > Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.

          Is there anything about these techniques that are raspberry pi specific? It seems like they're using lasers to identify and flip particular bits in registers.

          1. bob1029 · · focus · HN ↗
            There are HSMs that are effectively immune to this attack by way of their construction and packaging. You need an optical path to the secure device. The only way to get at this is to tamper with the tamperproof part of the system.

            Some very high end HSMs must be actively powered at all times which makes disturbances in their local environments detectable at all times as well. Getting lucky and drilling through a part of the enclosure that isn't directly protected won't help you if a barometric pressure sensor is tripped as a consequence of breaking the hermetic seal.

            1. stickfigure · · focus · HN ↗
              Are any of these tamper-proof chips in my phone or laptop?
              1. throwaway81523 · · focus · HN ↗
                I expect typical smart cards like the one in your credit card are harder to crack than the raspberry pi was. Those cards are (or were) also used in TV set-top boxes and back in the day, there was a decades-long arms race between the chip makers and cable TV pirates. The TV pirates were also willing to make large expenditures to crack the chips so they could clone them and sell the clones. There's more about this in Ross Anderson's book "Security Engineering".
                1. ironqcold · · focus · HN ↗
                  I’m actually curious now. Thanks, you’ve given me something to do this evening.
                  1. bigiain · · focus · HN ↗
                    Same. I wonder if my Yubikeys have anything to mitigate this sort of attack. My gut feel says that at their pricepoint and form factor, probably not.
                    1. crote · · focus · HN ↗
                      A Yubikey is basically a single chip and a bunch of plastic. At their $50 price point, there's plenty of room for some chip manufacturer to skim off a couple of dollars per chip to add an additional metal layer for a tamper protection mesh, and some other gizmos.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.