logoalt Hacker News

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

123 pointsby synacktoday at 4:54 PM39 commentsview on HN

Comments

BitBangingBytestoday at 7:02 PM

I appreciate all the details they provide in the post. The $250k in lab gear is useful when initially discovering, exploiting and documenting attacks like this.

Definitely doable in a home lab for under $25k in equipment, likely under $10k.

Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).

https://youtu.be/URmI1VVilek

show 1 reply
bybtoday at 7:28 PM

The RP2350's secure enclave made it particularly attractive for use as a Yubikey alternative.

There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.

show 1 reply
jacquesmtoday at 5:47 PM

That's reminiscent of when we first found out that if you opened up dram chips you could use them for imaging. Of course the scale at which this is done is extremely impressive.

stackghosttoday at 5:23 PM

> The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

Not super practical, but neat attack

show 5 replies
Fred27today at 5:31 PM

There's always an XKCD... https://xkcd.com/538/

show 1 reply
brcmthrowawaytoday at 6:25 PM

Now it can be done for Apple iPhone. Apple is cooked.