3 ms·
You can’t digitally do so, no. You would have to physically interact with the device to change how the circuit operated, or else the only way for the CPU to ac
by FakeComments 8y ago
You can’t digitally do so, no.
You would have to physically interact with the device to change how the circuit operated, or else the only way for the CPU to access the cryptographic data is by allowing a different specialized circuit to unlock a value based on analog input.
You can’t meaningfully “bypass” that digitally, unless you already know the secret. So if the auth flow depends on that secret, it can’t bypass the analog sensor feeding in the values to unlock it.
The bypasses we see are where you can, eg, attach a debug cable to feed in values without going through the sensor (which is a non-digital interaction). Or bugs in correctly implementing the logic, eg, the crypto chip accidentally exposes information.
It’s much the same protection a yubikey left in the side of your laptop provides: someone physically at the device pushed a button, with a cryptographic witness that’s hard to fake.