3 ms·
Aedan desoldered the RP2350 and physically cut the copper trace feeding voltage to a pin. Then he proceeded to use voltage glitching and was pretty open about h
by sounds 2y ago
Aedan desoldered the RP2350 and physically cut the copper trace feeding voltage to a pin. Then he proceeded to use voltage glitching and was pretty open about how lucky he was, or in other words how unlucky Rasperry Pi Ltd. was for the attack to work.
Doesn't this sound like the RP2350 is "secure enough"? Like you mention, if the attacker can send a unit to an MCU Break service, it's game over already.
- oytis 2y agoThese are all operations that only need pretty cheap and available equipment, so I think you can't call it secure enough
- immibis 2y agoThe parameters of the challenge were apparently that you could do anything at all.
- crest 2y agoThe problem is that this isn't an attack against a single chips unique code signing key, but against all RP2350 ever produced with this hardware revision. The problem can't be fixed in software. Now the attack doesn't require anything fancier than a hot air gun, and an interposer board to isolate the USB_OTP_VDD pin for glitching, and a pair of steady hands.