3 ms·
> With the device in their possession they can extract software from the embedded system chip on the device to obtain the software running on it. By reverse eng
by ctz 9y ago
> With the device in their possession they can extract software from the embedded system chip on the device to obtain the software running on it. By reverse engineering this software they can learn secrets in the memory of the onboard microcontroller.
Hoping to keep secrets from a physical attacker on a general purpose microcontroller is an excellent example of an IoT security anti-pattern. It's a shame the author missed the wider point.
- gol706 9y agoCan you really protect the device software if the hardware encryption element is separate from the microcontroller? Wouldn't it be trivial to sniff the decrypted cypher text of the software with a logic analyzer on the pin between the microcontroller and encryption ASIC even if you can't get the actual key out of it?