35 ms·
Full key extraction of Nvidia TSEC
- snthd 5y agoWhy are there valuable keys on the device? I (wrongly) assumed the device would only contain public keys to verify signed code.
- Namidairo 5y agoThey're AES keys, so the keys to decrypt and encrypt are the same. (Symmetric key)
- snthd 5y agoTo answer my own question, it's because the games are (symmetrical) encrypted. Skimming switchbrew it looks like there is public key crypto as well. https://switchbrew.org/wiki/NRR https://switchbrew.org/wiki/NRR So this key leak doesn't mean homebrew can be signed for unmodified consoles.
- vigneshdasan 5y agoGST on IT sector will attract 18% on software services provided by software companies. https://www.breziot.com/ https://www.breziot.com/
- punk_ihaq 5y agoHow is this remotely relevant to the post or any other comments? Please do not spam.
- tomc1985 5y agoI've been out of the security game for a while, this almost reads like fiction. Good god this is nuts. I've heard of extracting keys with timing attacks but this is even more impressive! Also, apparently the Switch perma-pwn got pwned? Sad face... Also also, I hope other popular cryptoprocessors aren't so vulnerable?
- scandinavian 5y ago> Also, apparently the Switch perma-pwn got pwned? Sad face... All erista units (the ones with the bootrom flaw) are still pwnable. 6.2.0 was released on November 19, 2018 - first indication of a new hack was posted on twitter Nov 24, 2018 by @elmirorac and atmosphere 0.8.0 was released on Nov 29, 2018. So the fix he talks about in the paste lasted for around 10 days before a new one was generally available. That's why he says: > And it would have been perfect if not for the many security flaws in TSEC secure boot.
- Mindwipe 5y ago> Also also, I hope other popular cryptoprocessors aren't so vulnerable? You might be surprised, but also this chip wasn't intended to be used to secure a chain of trust but had to be press ganged into service after being let down by the main bootrom, which was done by a team at NVidia without much experience of doing these things and made a lot of elementary errors. And being used for a games console is painting a big target on your back. But ultimately a lot of secure chipset areas have been subject to a lot of... learning on the job shall we say. Things are much better than they used to be, but you don't have to go back many years before things get very hairy. People constantly say they want more OS version support for Android, but I would not want to use a five year old processor from Samsung or Qualcomm if I cared about the hardware backed security on my phone.
- my123 5y ago> but you don't have to go back many years before things get very hairy For the NV TSEC-equivalent Falcon successor on Ampere, it’s indeed not vulnerable to this attack because that security subsystem was made much more secure. But that’s an arch released in… 2020.
- mschuster91 5y ago> People constantly say they want more OS version support for Android, but I would not want to use a five year old processor from Samsung or Qualcomm if I cared about the hardware backed security on my phone. What I would really like is a modern Android that doesn't brick half the security features by e-fuse when I root it and many apps refuse to run properly afterwards - why the fuck, for example, does the PayPal app refuse fingerprint unlocking after rooting but other apps don't?! All this incentivizes me as the user is to choose an insecure password that I can actually remember.
- toxik 5y agoAre these numbers “illegal” to share like the BluRay key?
- edg-l 5y agointeresting related article: https://en.wikipedia.org/wiki/Illegal_number https://en.wikipedia.org/wiki/Illegal_number
- IiydAbITMvJkqKf 5y agoBased on the file contents, these are just the sha256 hashes of the keys, not the keys themselves.
- toxik 5y agoRight, but the actual key itself then?
- Y_Y 5y agoLike this? > sha256(csecret_01)=43449338c1bc8ceb1b3232a611f955f9095254f492117a158528589cd16f2930 NVIDIA TSEC code signing key Hopefully not.
- throaway46546 5y agoRemember Digg?
- a-dub 5y agoso how does this voltage glitching stuff work exactly? are caps to ground/buffers removed/defeated? is it timing dependent? (sounds like they're sending i2c messages to the power circuitry here?) do people do things like setup precise triggers or hook up function generators to kick the supply voltage around and just wait to get lucky?
- pjc50 5y agoHilariously it appears you can just direct the system to turn down its own supply voltage for you (I2C to the PMIC, as you spotted), and that one of the levels has a bit error rate that's low enough to run programs most of the time but triggers a bit flip in AES often enough to leak the key.
- bradfa 5y agoA properly designed crypto subsystem that cared about security would detect the voltage drop and either refuse to operate or would have its own local power regulation circuits such that a system level voltage reduction wouldn't impact it. I presume the CPU here was VERY cost conscious and so trade-offs were made. I have no background in gaming but have worked with flawed "security" solutions. Often the business does not care that the engineers explain how flawed some security thing is before release, if there's more money to be made by not fixing it then it won't get fixed. Often doing all of the right things is MUCH too expensive, either in dollars, size, or power.
- baybal2 5y ago> would have its own local power regulation circuits such that a system level voltage reduction wouldn't impact it. How do you know if external voltage is low if you check it against... a voltage derived from it?
- thebruce87m 5y agoIsn’t that what bandgap voltages are for? https://en.m.wikipedia.org/wiki/Bandgap_voltage_reference https://en.m.wikipedia.org/wiki/Bandgap_voltage_reference
- Faaak 5y agoHoly cow. Reading these recaps I feel a lot the Impostor Syndrome. I think I'm competent on what I do, but when I see those guys it's hard not to feel really dumb. Congrats to them !
- vadfa 5y agoTake into account that this particular post glosses over a looot of stuff. A more detailed write-up would not make you feel that dumb.
- nkurz 5y agoMaybe, or maybe not. Presumably that "more detailed write-up" would be something like the third footnote: https://yifan.lu/2019/02/22/attacking-hardware-aes-with-dfa/ https://yifan.lu/2019/02/22/attacking-hardware-aes-with-dfa/. Despite being much more detailed, I still felt just about as dumb! :)
- baq 5y agoon the contrary, it'd make me feel a lot dumber...
- wingerlang 5y agoYou can do a lot with persistence too. I recently tried to reverse engineer some software protection. Ultimately I decided to cut my losses but the 2-3 weeks I spent on it was a very gradual chipping into more and more advanced stuff. Now imagine having years of experience, and chipping away over years. One "wow" moment in a blog article might have taken 3 months of headaches to reach.
- fragmede 5y agoReading the blog post, it sounds like a supergenius' long weekend, so the timeline O(months) is not to be skipped over. 1% genius, 99% perspiration. Or more recently, "an overnight success after trying for 10 years".
- 5y ago
- sarahmike 5y agoI they can make online so I decided to look into it. Well, it was all true and has totally changed my life. This is what I do. Copy Here——>>>www.foxlineblog.comᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵ
- 1_player 5y agoAs a boring software engineer nowadays, these hackers "for fun and profit" make me proud of our profession. They're like a Robin Hood version of Alan Turing & co. working on cracking the Enigma encryption. No matter how tight the black box is, there is always a gap somewhere. I've done some reversing when I was younger, cracked some software and hardware locks, there's nothing as exhilarating as breaking through something that looked impossible. Well done!
- iamtedd 5y agoI love hearing these stories too! Here's a video of someone finally cracking into the Sega Saturn well after the console was current commodity: https://www.youtube.com/watch?v=jOyfZex7B3E&t=202s https://www.youtube.com/watch?v=jOyfZex7B3E&t=202s
- JohnBooty 5y agoHe eventually released a commercial product, the Satiator, and I'm happy to say that it works great and is very well supported by the creator himself and the community! For those unfamiliar, the Satiator is an adapter of sorts that lets you load Saturn ISOs onto an SD card and play them via the Saturn's MPEG adapter slot. Unlike many solutions on various consoles that bypass the optical drive, no hardware modifications are required. Your Saturn stays intact; it's truly plug-and-play. This sort of thing is important. Consoles (specifically moving parts, like the optical drives) and physical media from the 90s are failing. Surviving consoles and games can be quite expensive; even thousands of dollars. Emulation is imperfect and introduces lag. Satiator and other flashcarts let us play these games on original hardware and bypass these issues.
- dylan604 5y agoNot game related, but this is what I like about the MagicLantern hack for Canon cameras. It's just some data on your card that gets loaded at boot. If you use a card without the data on it, the camera boots/peforms as a regular stock camera. No hacking of the software on the camera itself.
- sarahmike 5y agoI they can make online so I decided to look into it. Well, it was all true and has totally changed my life. This is what I do. Copy Here——>>>www.foxlineblog.com
- louthy 5y agoHeh, I had a little laugh to myself reading this bit: > (2) its own "secure boot" As soon as you see the quotes, you know what's coming! It's like Chekhov's gun :)
- londons_explore 5y agoThese appear to be sha256 hashes of the keys, not the keys themselves...?
- zarzavat 5y agoI assume that's so it doesn't get immediately DMCA'd. They can either distribute the keys separately or other people follow the paper and the keys will become known.
- encryptluks2 5y agoThis seems to indicate that this involves the Nintendo Switch, but that it only involves older models where the first layer of security was broken and now a second. Wouldn't the new models have patched the first layer of security by now where this wouldn't result in anything of value?
- freeone3000 5y agoYes, HAC-0001-001 (better battery life) and HDH-001 (Lite) use a new ROM revision with this patched out. But there are a lot of original Switches out there.
- xaduha 5y agoWhy aren't more devices use smartcards for signing/crypto? They are omnipresent, satellite TV receivers had them, phones have them, banking cards ARE them. And yet gaming console manufacturers would rather invent their own measures to combat pwnage/piracy.
- deleted 5y ago[deleted]
- mschuster91 5y ago> satellite TV receivers had them And regularly get their card security schemes busted. The advantage that smartcards currently have is that not many people are looking into their security outside of pay-TV pirates. Phone users don't have a need to hack their own SIM cards, friends of OpenBTS simply use blank SIM cards, bank users don't need to hack their own cards, and card cloners have a hard time getting physical access to the chip on a victim card for long enough to run a software-based attack (since the ATM eats the card and spits it out when done, it is easy enough for a skimmer device to clone the stripe while the card passes, but outright impossible to establish electrical contact with the chip). What is interesting to hackers is anything where NFC can be exploited, and as a result - at least to my knowledge - there currently is no tag-based authentication that can't be cloned.
- xaduha 5y ago> And regularly get their card security schemes busted. It was wild west, proper ones were never cracked to my knowledge. But it's probably safe to say because of that they are as secure as they are now. https://en.wikipedia.org/wiki/Conditional_access#Digital_systems https://en.wikipedia.org/wiki/Conditional_access#Digital_sys... > there currently is no tag-based authentication that can't be cloned. Smartcards use ISO 14443, not NFC. Those are related standards I think. https://en.wikipedia.org/wiki/ISO/IEC_14443 https://en.wikipedia.org/wiki/ISO/IEC_14443 MIFARE tags and cards (which you can clone) are not smartcards (which you can't clone) https://en.wikipedia.org/wiki/MIFARE https://en.wikipedia.org/wiki/MIFARE
- 5y ago
- sva_ 5y agoThe concept of undervolting the chip, causing bitflips, to do a differential fault analysis[0] seems like a stroke of genius. I had no idea AES could be broken in such a fashion, of interfering with just the last 1-2 rounds of the cipher. I wonder if it will be mitigated by requiring a larger minimum voltage? [0] https://en.wikipedia.org/wiki/Differential_fault_analysis https://en.wikipedia.org/wiki/Differential_fault_analysis
- ParadisoShlee 5y agoThere is a series of videos on the ChipWhisper to recover RSA keys and other fault injection stuff. Super interesting security field.
- exikyut 5y agoHa, that mentions "DFA was also applied on AES", citing a 2005 reference. Is the OP article being understatedly humble? ;)
- Mindwipe 5y agoEither that or pausing crypto operations without the required voltage, but that reduces your fault tolerance.
- baybal2 5y ago> I wonder if it will be mitigated by requiring a larger minimum voltage? How would you detect low voltage without a reference voltage?
- hashimotonomora 5y agop-n junctions have a threshold forward voltage.
- frumiousirc 5y agowhich is temperature dependent
- baybal2 5y ago
- oh_sigh 5y agoDoes this txt seem to end early for anyone else? How does one go from the bit-flipped output to the key?
- nemothekid 5y agoThat's covered in the referenced article, https://yifan.lu/2019/02/22/attacking-hardware-aes-with-dfa/ https://yifan.lu/2019/02/22/attacking-hardware-aes-with-dfa/, in the `Extracting keys` section
- sydthrowaway 5y agoSeriously, security is an utterly pointless field
- Jugurtha 5y agoI love everything about this. It has brought joy to my day.
- marcodiego 5y agoSome features in NVIDIA chipsets, like changing the operating frequency, needs (hardware checked, I think) signed binary blobs. This prevents the open source nouveau driver from achieving good performance. Does this hack helps in this front?
- SSLy 5y agono, this is about Tegra platform
- salawat 5y agoThat doesn't necessarily rule it out. Cryptography is one of those things that once you get it down, you stick with it. It is entirely possible this may give enough insight into Nvidia's SOP with cryptography to extend the PoC proven on Tegra to something like their firmware signing functionality in GM 204 cards. At least, I haven't seen anything that stands out enough to downright disclude the possibility from possibly nudging things down the road, in theory.
- salawat 5y agoThere it is. Money shot in one of the references: >Because this is a (unmitigable!) hardware issue in all Falcons which have SCP, not just TSEC -- we were also able to use the same attack on the Falcon unit used for GPU power management, recovering its (different) signing key as well. In short, the same methodology, assuming you put a crap ton of time into reading this, and really grokking it, suggests this attack could be applied not just to Tegra, but any secretful Falcon.
- pabs3 5y agoSeems the other TSEC exploits mentioned might refer to these: https://github.com/CAmadeus/falcon-tools https://github.com/CAmadeus/falcon-tools https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34393 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3439...
- rdpintqogeogsaa 5y agoThere's also an extensive write-up at https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-over-horizon.html https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-...
- jesuspiece 5y agoHardware attacks never cease to amaze me. nice work, thanks for sharing
- yborg 5y agoIt seems from accomplishments like this from amateurs that state level actors will have compromised any current "secure" or "trusted" computing platform.
- make3 5y agoI'm not sure why you claim that this is an amateur. Yes, this is likely a project done in their spare time, but there is no reason to think that this person is not a professional security analyst
- motohagiography 5y agoHat is off to the author for executing like that. I feel like I missed out by never playing games, as cracking them seems like the real game behind the game. From a design perspective, this is why you don't have your entire ecosystem depend on a shared secret stored in secure hardware, even if they're written when the chip is still in the flasher at the fab. You need either to diversify your keys in the flasher, or do an initialization/personalization protocol to update the keys to new unique per-console ones so that a crack like this isn't portable across every other customer device. As a design consideration, it means the customer has to be online to personalize the device to get their unique keys, but that's the trade off. The beauty of demonstrating this attack is that if you think game consoles with security modules are vulnerable to having ecosystem compromising shared secrets extracted, wait until you see phones.
- bo1024 5y ago……or this is why you let people own the hardware they purchase and give up on this ridiculous “secure” boot idea?
- naikrovek 5y agosome people forget, or don't know about, Atari's first consoles, which had zero "secure" features and the enormous mess that caused. the entire home video game industry in the US virtually died for a while because of all the crap games that were produced. imagine mobile-like shovelware games selling for $60 each for a while, and consumers being unable to tell which games were good and which were bad until you took them home and played them. then, finding out you can't return the crap ones because too many other people were returning those same games, and the retailers couldn't absorb the cost. then, seeing all console video games in "bargain bins" for $1-$2 each and even then extremely few people were buying them. I recall seeing bins going virtually untouched for months. parents just stopped buying games for their kids' consoles, nearly completely. the idea of a home video game console was so negative that Nintendo needed to call the NES an Entertainment System in order to get their device into homes. That Nintendo Seal of Quality really meant something, and only Nintendo could manufacture the lockout chip that prevented unauthorized games from running, so that Seal of Quality really had weight and it basically meant "no shovelware games" for it's entire existence. Entrepreneurs showed Nintendo and Atari what happens when you have no console security: that lots and lots of people will eagerly crush the entire market in exchange for a bit of money. Nintendo has not forgotten this lesson, and they're not likely to.
- 1MachineElf 5y agoWhat is a TSEC? EDIT: Well, some clever guy ;-) reminded them that the T210 chip (the main CPU) has a proprietary NVIDIA "security processor" called TSEC, which has: [2] (1) its own SRAM (protected from the rest of the system) (2) its own "secure boot" (protected from the rest of the system) (3) bus mastering capabilities (4) and.. is able to DMA to ARM7's memory
- jaywalk 5y agoTegra Security Co-processor
- ChuckMcM 5y agoWow, this was the first I had read about m2m i2c injection hacks to mess with the PMIC. That is a clever trick!
- JohnCurran 5y ago> If you can get 1-2 bitflips in the last two rounds, you can solve for the key. What about the bit flips allows the key to be solved for? That is the part of this I don't understand
- marcan_42 5y agoThe security of cryptographic primitives relies on the mixing that happens from the first round to the last round. If you can analyze the input-output relationship of a single round, you can easily derive the round key (and the way the AES key schedule works, if you have any round key you can run it backwards to derive the original key). Bit flips in the middle of the algorithm allow you to do just that; if you have a bit flip in the second to last round, that'll have a specific effect on the output, and that effect will depend on a small part of the round key. Collect enough samples and you can solve for it. It turns the problem of brute forcing a 128 bit key into the problem of brute forcing a few bits at a time, because with only a round or two there is very little diffusion, i.e. every output bit only depends on a few key bits. I've done the same thing to break "white-box" AES implementations, which are software versions of AES with the algorithm obfuscated and the key baked into it, in the form of flattened per-round-byte lookup tables (this concept is complete snake oil, but a few companies insist on selling it; they claim it's hard or impossible to get the key out, but this method works every time). You can introduce faults by patching the code or using a debugger to change state in the last round or two, and compute the key from the results. I did a targeted attack where I surgically introduced faults by replacing intermediate values with ones from a different input (which works even when the algorithm uses redundant, booby trapped encodings, which is another feature these vendors peddle), but in most cases you can also just literally randomly corrupt execution and use the same script Yifanlu wrote, just like a random hardware glitching attack.
- hkopp 5y agoThe magic to me is that the CPU glitches are caused completely on the software side. With dedicated hardware such as flying probe testers this attack is state-of-the-art afaik. But glitching the CPU only with software, i.e., causing hardware bugs only with software is what really surprised me.
- jturpin 5y agoI'm sure this took a lot of effort and more knowledge than I'll ever have. All of this effort could have gone to doing something constructive, and instead it's gone to breaking a system so that a small handful of people can run software (be honest, game emulators) on it, and presumably support further piracy of the system. There are already a trillion devices out there that can run emulators, we don't need another one.
- Siira 5y agoYes, all the effort all these mega corps put in jailing us could be put to do something actually positive.
- brokenmachine 5y agoWhen $NEW_PRODUCT is released, you must dispose of $OLD_PRODUCT and consume $NEW_PRODUCT.
- hsbauauvhabzb 5y agoWhat is the implications of breaching these keys?