4 ms·
> you can just sniff the i2c bus to learn the keys RMASK and WMASK, which smelled not useful to you, are there exactly to prevent this from happening.
by dimonomid 8y ago
> you can just sniff the i2c bus to learn the keys
RMASK and WMASK, which smelled not useful to you, are there exactly to prevent this from happening.
- jiveturkey 8y agolol no. this is almost not even worth a response. the key managed here https://github.com/conorpp/u2f-zero/blob/master/firmware/src/u2f_atecc.c#L278 https://github.com/conorpp/u2f-zero/blob/master/firmware/src... and here https://github.com/conorpp/u2f-zero/blob/master/firmware/src/u2f_atecc.c#L208 https://github.com/conorpp/u2f-zero/blob/master/firmware/src... just means that the "actual key" (unmasked) only lives in MCU memory for a short time -- the time from when the mask is applied and then until return to caller and memory is cleared, in the enrollment case I linked. In the authenticate case, it lives quite a bit longer because the stack space used for key storage isn't zero'd. The atecc508 doesn't use or know how to use the mask. The actual key used for the encryption is passed in the clear over i2c. (note that the key derivation you suggest is wrong because of the extra xor masking.)
- conorpp 8y agoThis is a bit late, but the atecc508 does apply a random mask, see PrivWrite command in datasheet. http://ww1.microchip.com/downloads/en/DeviceDoc/20005927A.pdf http://ww1.microchip.com/downloads/en/DeviceDoc/20005927A.pd...
- deleted 8y ago[deleted]