4 ms·
Attacks on the ICs are probably possible if corners are being cut. Purely speculation but if this was the case I would be glad it was called out so fast.
by msane 10y ago
Attacks on the ICs are probably possible if corners are being cut. Purely speculation but if this was the case I would be glad it was called out so fast.
- r00fus 10y agoWhat do you mean by "attacks on the ICs" - sabotage?
- deleted 10y ago[deleted]
- kbart 10y agoHow? I really doubt it as these ICs have no CPU, flash or anything else that could be programmed externally. Here's a random example of how one look like: http://www.ti.com/product/bq24232ha/datasheet http://www.ti.com/product/bq24232ha/datasheet
- gambiting 10y agoPSP was hacked through the battery. Basically Sony had a "magic" battery that would report certain ID, that they could use to flash any firmware they wanted. Well, someone figured this out, and as it turns out, you could use a hacked PSP(hacked through one of the existing exploits) to flash a different ID to the battery - from that point onward it would act as a "magic" battery and could be used to flash any PSP. So yeah, the IC in the battery was nothing more than a tiny bit of memory containing the ID, but ultimately, that was the downfall of the whole PSP ecosystem, as you could use a hacked battery to reflash any PSP, regardless of its firmware, so sony had no way of patching this.
- kbart 10y agoI' not aware of this particular case, but over-the-shelf charging IC is definitely not enough to accomplish that. That sounds like a wider, system problem. Anyway, that's an interesting story, I'll check it - thanks.
- gambiting 10y agoThere are some links with explanations if you want to read up on it :-) http://www.krizka.net/2008/02/10/what-is-pandoras-battery/ http://www.krizka.net/2008/02/10/what-is-pandoras-battery/ http://www.instructables.com/id/PSP-Hacking-Guide/step2/Pandora-battery/ http://www.instructables.com/id/PSP-Hacking-Guide/step2/Pand... https://geekindisguise.wordpress.com/tag/psp-pandora-battery/ https://geekindisguise.wordpress.com/tag/psp-pandora-battery... "This is a battery with its serial changed to 0xFFFFFFFF. When a PSP battery serial number is changed to 0xFFFFFFFF, or unreadable, the PSP boots the IPL from sector 16 on the physical drive (the Magic Memory Stick). This unlocks the service mode of the PSP and launches the IPL from the Memory Stick (instead of from flash0). A regular battery can be made into a JigKick via hardware or software methods."
- kefka 10y agoI know the guy who did it. I sat behind him until I started my new job this week. Cool dude.
- tim333 10y ago>these ICs have no CPU, flash or anything else that could be programmed All my laptop and phone batteries, if you view the battery info, have the name and date of manufacture, cycle count and approximate percentage remaining. This info is stored in the battery, not the device, so there must be memory and something like a processor. Edit: There's some info here "Battery Firmware Hacking Inside the innards of a Smart Battery" https://media.blackhat.com/bh-us-11/Miller/BH_US_11_Miller_Battery_Firmware_Public_WP.pdf https://media.blackhat.com/bh-us-11/Miller/BH_US_11_Miller_B... With helpful advice like: >Macbook batteries ship with a default unseal password (0x36720414). This was found by reverse engineering a Macbook battery update. On Macbook batteries, the full access mode password is also hardcoded and default (0xffffffff). >The actual firmware is machine code for a CoolRISC 816 8-bit Microprocessor. This was found by Dion Blazakis by googling some opcodes from the end of the firmware. Texas Instruments considers this information proprietary and would not reveal it. >I this work, I provide API functions which can be used to communicate with the battery. This allows the ability to make arbitrary configuration changes as well as dumping of the data flash and instruction flash. I provide IDA Pro scripts to disassemble the machine code from the firmware. We provide a way to disable the firmware checksum as well as to make arbitrary changes to the smart battery firmware. Due to the nature of the Smart Battery System, changes made to the smart battery firmware may cause safety hazards such as overcharging, overheating, or even fire. Which sounds quite promising if you want to make Stuxnet like malware to toast peoples Macs.