5 ms·
Nice acoustic hack. It's also amazing what you can do with a simple FM/AM radio to perform short range tempest sniffs. No doubt some amazingly clever tricks can
by nonrandomstring 3y ago
Nice acoustic hack. It's also amazing what you can do with a simple
FM/AM radio to perform short range tempest sniffs. No doubt some
amazingly clever tricks can be done with SDR. If it runs code, it
leaks EMR.
- bayindirh 3y agoAnother incredible category of attack is power analysis / power starvation attacks. IIRC, a research group succeeded to extract the private key by power starving a server and analysis its power draw at the same time. OpenSSL had to implement some randomization to thwart it. Looks like it's still something: https://medium.com/@shipeiqu1998/power-analysis-attack-how-to-crack-your-smart-card-143d86193853 https://medium.com/@shipeiqu1998/power-analysis-attack-how-t...
- demondemidi 3y agoIf you look at modern crypto libs you’ll see most operations require an rng function. This isn’t because random data is added to the operation, it is to make sure the operations on the data are obscured during lengthy operations that can be replayed for differential power analysis. Like ECDH secret mixing will add random numbers to the points and the normalize them out after the point multiply. It’s pretty damn clever.
- TeMPOraL 3y agoSo I guess step 1 of modern cryptanalysis is, compromise the RNG.
- nonrandomstring 3y agoI think step 1 of getting something like secret keys out of Xbox or whatever would be learning to 3D print micrometer scale antenna arrays and use those fancy broadband SDR chips someone was talking about the other day with some image source and phased array tricks used in radar to precisely sniff out whats going on and where.
- nonrandomstring 3y agoIndeed, constant execution time, block padding, resource use obfuscation... it all helps, but in the end different bit patterns moving around produce different EM waves and advanced DSP methods can remove noise and find those patterns. What do they say? Possession is nine tenths of the law. If I have it in one hand and some time on the other, eventually I'll find out how it works. A security posture based on any other assumption is naive. Which is why appliance computing and DRM using "trusted consumer modules" is a fools errand.
- HeatrayEnjoyer 3y agoIs it really? The Xbox One has been around for years and yet online cheating is non-existent. The only way that's possible is if no one has extracted the enclave private keys to sign modified data. And game hackers are notorious for going the extra mile (development Xboxes have been physically stolen from Microsoft headquarters in Redmond) so it must be very difficult.
- aidenn0 3y agoI assume the enclave private keys are not on the Xbox One. Pretty sure GP was talking about extracting keys from devices that have the keys on them.
- HeatrayEnjoyer 3y agoThe keys are in the Xbox, where else would they be? Each console has a unique endorsement key burned in at silicon level. This is also how undefeatable hardware bans can be issued, blocklisting the key.
- 01HNNWZ0MV43FF 3y agoDRM works in practice. Most users end up not side-loading things on their phones or playing homebrew on their consoles, even though it's theoretically possible. Even piracy is way down, to my dismay.
- 3y ago