4 ms·
It does, because they can't retrieve the keys from memory otherwise - Unlocking the bootloader is essentially opening the phone up to malicious code execution b
by stormcloud 11y ago
It does, because they can't retrieve the keys from memory otherwise - Unlocking the bootloader is essentially opening the phone up to malicious code execution by anyone with physical access.
- gherkin0 11y agoIt would be more difficult and model-specific, but couldn't they attach a device to read the RAM chips directly? To perform this on most modern phones, they have to disassemble it anyway to be able to toggle the power quickly enough (since there's no user-replaceable battery).
- baobrien 11y agoThey probably wouldn't be able to attach anything to the ram directly, as the ram chips on modern phones are soldered down BGAs. To get at the pins, they'd have to de-solder them, which would heat up the chips in the process. It might be possible to get at the ram over JTAG or some other debug bus in some devices, though.
- prutschman 11y agoThis is probably in the realm of "if you're subject to this level of attack you have bigger problems", but, I wonder if it would be possible to laser drill after-the-fact micro vias through the PCB to get at all the BGA pads with absurdly small probes.