4 ms·
> there is readout protection built into the SoC I have managed to bypass readout protection on STM32F1 with just a few nights of hacking and $2 in parts; I su
by kosma 10y ago
> there is readout protection built into the SoC
I have managed to bypass readout protection on STM32F1 with just a few nights of hacking and $2 in parts; I suspect F4 isn't much different. I wouldn't trust any general purpose MCU in this regard.
- mkj 10y agoNice, I'd wondered how hard that would be. Could you share details?
- kosma 10y agoThe FPB (flash patch and breakpoint) peripheral on Cortex-M3 allows live-patching the flash contents; this allows you to temporarily change the reset vector. That, plus careful supply voltage glitching to reset some peripherals but not other, and the device is pwned.
- lisper 10y agoNice! But it sounds like it would not be effective against RDP level 2.
- lisper 10y agoThe RDP on the F4 is more capable than the F1. The F1 only has level 1 RDP, the F4 has level 2 as well. If you can break level 2 without decapping the chip that would be big news (and probably result in a class action lawsuit against STM). Can you describe how you did it? [EDIT: Never mind, I see you already answered that in the other branch of this thread.]
- kosma 10y agoI had a look at the documentation and it seems they finally made it a JTAG fuse and not just a value in program memory. Nice move.