4 ms·
> Assuming this updates the loader It doesn't. The model I presented presumes that it is unchangeable. > anyone with physical access for five minutes can perm
by codys 11y ago
> Assuming this updates the loader
It doesn't. The model I presented presumes that it is unchangeable.
> anyone with physical access for five minutes can permanently brick the phone, without opening it
Pick one:
- you can always get your phone working, even if you forget your key & only you can apply updates to any software on the phone. Anyone can replace the loader (but this wipes all other data).
- you can always get your phone working, even if you forget your key & only a third party can provide new versions of the loader.
- if you forget your key, your phone is permanently bricked.
> Also, how can loader A modify itself?
It can't.
In general though, it's fairly straight forward to have code copy itself into ram & run from there while overwriting it's source. The problem is that opens the potential to brick the phone (just like any method that allows updating the loader).
To avoid bricking in all cases, one _must_ assume that there is some un-replaceable software (or hardware mechanism to start software).
- ikeboy 11y agoI'm coming around to believing it's possible. Now I'm wondering whether you can place malicious RAM in the phone that changes instructions on the fly. Is that feasible?
- codys 11y agoLots of things become possible once one is willing to decap ICs to get at the internals. I'd expect security consious parts (ie: all of the theoretical "loader A") would need to run in SRAM (ie: ram that is in the same IC and thus harder to get at than external DRAM chips) or some other mechanism. At that point, it becomes a question of physical hardening within the ICs. Some manufacturers have done things like put metal layers over fuses (to prevent them from being changed), I'd imagine the same could be done (at some cost) for a larger area of the chip. I'd imagine HSMs (hardware security modules) and TPMs (though these aren't as good) probably implement some of that. There also exist some chips targeted towards security purposes (not aware of any processors off hand) that could be used .
- ikeboy 11y agoWouldn't the regular ram also need hardening? If I can modify the ram, I can change the OS that's loaded to ram. Does this hardening slow it down?