6 ms·
Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug
- deleted 14d ago[deleted]
- stackghost 14d ago> The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment. Not super practical, but neat attack
- mrlambchop 14d ago250k is not a bad investment for a company doing "reverse engineering as a service" - say 1k a pop to extract the firmware. Naturally, a good business idea for somewhere in the world with less regulations...
- paulnpace 14d ago> $250,000 of laboratory equipment *currently
- stavros 14d ago$300,000 next year.
- k12sosse 14d agoWe're already up to 400,000 just today.
- TeMPOraL 14d agoIn 5 years, either $400,000 or $50 and a hammer, depending on whether the core piece of the process aligns with the needs of some fast-growing consumer tech product like e.g. drones.
- dist-epoch 14d agoI think GP was making a joke about RAM prices. Makes me wonder what is the effect of the RAMpocalypse on drone prices.
- TeMPOraL 14d agoMaybe. I was referencing my own realization earlier today, when I was wondering if I can DYI a ground-penetrating radar to scan the allotment garden for hidden "surprises". A ground-penetrating radar is something I learned about as a kid watching a popular science videotape, back then a stupidly expensive high-tech piece of professional equipment. But it hit me that there are two main forces keeping such technologies stupidly expensive and inaccessible to general public over time: costs of knowledge that went into their design (protected by patents and trade secrets), and specialized parts made in unique way or from unique materials, that don't happen to have alternate applications. Nowadays, knowledge is not an issue - 20+ years is enough for all the relevant patents to expire, and information to have seeped through to the Internet, available in a combination of Wikipedia articles, textbooks, scientific papers, and blogs, plus we have good LLMs more than happy to synthesize that and transform into a DIY tutorial for dummies. Which leaves the parts. Whether or not you can DIY such a tech really hinges on whether you can find the critical components somewhere. If they're still unique, you're paying $$$ for procurement (and it makes more sense to try and score broken/used equipment off eBay or something). But there's a chance there's a close equivalent that's part of mass consumer or prosumer device, at which point you just buy it and strip it for parts. (Which way it is with ground-penetrating radars? Don't know, didn't bother to prompt an LLM with that question yet.)
- dist-epoch 14d ago[dead]
- MadnessASAP 14d agoRadar is cheap now, thanks to semiconductors getting smaller and faster the analog front-end which used to be a long expensive chain of components is now much smaller, the ADC is now faster, more accurate, and cheaper, the processor is now fast enough to keep up with a higher bandwidth signal. You could probably drive a very rough radar system directly off a Pico's GPIO and ADC, maybe toss in a decently fast op-amp for a receive amplifier. Where you will run into issues is processing radar signals into usable data. If you're happy with the results that radar was giving 30 years ago then it's fine and dandy, but the magic of modern radar is in the software, not the hardware.
- etdznots 14d agoLlms should make these cost even less im thinking $50 in 18 months?
- _trampeltier 14d agoSome people have such and other toys just at work and can use it in spare time.
- stickfigure 14d agoThat is peanuts for a nation-state actor.
- stackghost 14d agoSure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.
- ssl-3 14d agoThe RP2350 is an inexpensive microcontroller IC with reasonable performance and some very useful (and somewhat unusual) features in its PIO blocks. Why wouldn't a person build that into the heart of something important?
- sephamorr 14d ago"Important" and "tamper proof against a determined adversary" are very different goals.
- jacquesm 14d agoTamper proof against a determined adversary starts at 'call us' not at '$10'.
- stackghost 14d ago>Why wouldn't a person build that into the heart of something important? Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.
- rcxdude 14d agoRp2350s are advertised as having quite a few anti-tamper functions. They had a bounty when it launched to find similar vulnerabilities and they worked to patch the ones that were found. This is a lot more credible than a lot of advertised anti-tamper features.
- TZubiri 14d agoIt reads as impressive defense. Meaning that it's presumably not possible to get root with physical access on a live 50$ device without 250k capital
- Rohansi 14d agoThis is for a $1 microcontroller. I'm assuming you're talking about the Raspberry Pi computers based on the $50 cost and root.
- crote 13d agoIt's a $1 MCU, which will get embedded into a $50 device. If you're a company selling a cloud-plus-device product, then that 250k tooling cost and not-exactly-trivial attack process will be quite effective at stopping Chinese clones: with a unique per-device key there's no way they'll sell enough units to make a profit before you will inevitably ban their cloned key.
- TZubiri 12d agoWell not chinese clones, those are well funded factories with state su subsidies, but it will definitely stop rogue individual hackers. It's not even 250k cost, just 250k capital, it can be rented.
- Fred27 14d agoThere's always an XKCD... https://xkcd.com/538/ https://xkcd.com/538/
- orbital-decay 14d agoIt needs to be updated. Modern evil planners don't even need a wrench since they already have most keys given to them in advance by everyone, including nerds
- junon 14d agoCare to expand?
- mitxela 14d agoEver put your password into a website that used cloudflare? Ever registered an account with Gmail? Ever had an Android or iOS phone?
- bigiain 14d agoThat's cynical, but without doubt true for some people. I wouldn't want to be someone the NSA is "interested in". I wouldn't even want to be someone that a customer of NSO Group is interested in. (Just ask Jamal Kashoggi's family or friends) Hell, where I live they're about to give cops powers to let then hack your phone with a Cellebrite UFED at roadside stops. And it's not even just cops, fisheries enforcement officers Australia have been using UFEDs at least as far back as 2017 during illegal fishing investigations. If you're doing things that might make someone rich or powerful enough unhappy, or someone in law enforcement - you pretty much need to stop using the internet. And the bar for "how powerful" your potential threat is keeps dropping lower and lower. Just look at all the stories about local cops abusing Flock cameras to stalk ex girlfriend or people critical of them, how could anyone possibly believe those same sort of cops aren't going to use roadside phone forced data extraction tools in exactly the same petty and personal ways, and with exactly the same lack of oversight and consequences?
- jacquesm 14d agoThat's reminiscent of when we first found out that if you opened up dram chips you could use them for imaging. Of course the scale at which this is done is extremely impressive.
- xattt 14d agoFor the curious: https://hackaday.com/2014/04/05/taking-pictures-with-a-dram-chip/ https://hackaday.com/2014/04/05/taking-pictures-with-a-dram-...
- jacquesm 14d agoA lot earlier than that. https://www.cs.uaf.edu/2007/fall/cs441/support/dram_sensor_1984_whitehead.pdf https://www.cs.uaf.edu/2007/fall/cs441/support/dram_sensor_1...
- buescher 14d agoEven earlier than that. The cromemco camera and similar hobbyist projects dated from the mid-70s.
- jacquesm 14d agoI'm trying to date when we were first playing with this, but that was a messy period in my life and it is hard to put it all in chronological order. But I do know I had a driving license so it must have been around 87 or 88. The thing that I remember most clearly is that the images we made had a massive blank area where the chip was split into two halves with a bunch of stuff in the middle.
- buescher 13d agoMicron made one in the early eighties also and Steve Ciarcia promptly produced a DIY version for Byte.
- brcmthrowaway 14d agoNow it can be done for Apple iPhone. Apple is cooked.
- BitBangingBytes 14d agoI appreciate all the details they provide in the post. The $250k in lab gear is useful when initially discovering, exploiting and documenting attacks like this. Definitely doable in a home lab for under $25k in equipment, likely under $10k. Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50). https://youtu.be/URmI1VVilek https://youtu.be/URmI1VVilek
- throwaway81523 14d agoNice, thanks. I had wondered whether the $250K in lab gear is something that a serious HW security lab would already have on hand, as opposed to specialized expenditure for just this attack. I mean I rode in a $250K(?) motor vehicle a few days ago (the #2 SF Muni bus towards the Marina) but I didn't have to spend a lot to ride it, since it was already deployed. Nobody had to go out and buy it.
- junofan 14d agoHah, our new ones are $1.3 million. https://www.sfmta.com/media/44081 https://www.sfmta.com/media/44081 Perhaps driven by restrictions on federal grants? https://media.api.sf.gov/documents/Briefing_Book_-_Muni_Funding_Working_Group_-_October_2024_1.pdf https://media.api.sf.gov/documents/Briefing_Book_-_Muni_Fund... Some cool tech. Wonder if we optioned the inductive charging system. https://www.gillig.com/buses/battery-electric/#1731934845437-6ff757cd-619a https://www.gillig.com/buses/battery-electric/#1731934845437...
- laurencerowe 13d agoWow. Equivalent ones built in England are around 1/3rd the price £350k = $470k. https://www.bbc.com/news/articles/cjq45vw3n4go https://www.bbc.com/news/articles/cjq45vw3n4go
- 1attice 11d agoYeah but I bet the steering wheel is on the wrong side. ;)
- byb 14d agoThe RP2350's secure enclave made it particularly attractive for use as a Yubikey alternative. There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.
- octoberfranklin 14d agoThere will always be an arms race between safe-crackers and safe-builders. This is dismissive and glib. And it's the wrong lesson. You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race. The "arms race" exists because the security model for trusted hardware is intrinsically flawed. If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race. So stop doing this! Trusted hardware also has extremely negative externalities on the whole computing ecosystem. (*) or 45 years, if you exclude cryptosystems (56bit single-DES) used only because of silly export laws.
- deleted 14d ago[deleted]
- zephen 14d ago> This is dismissive and glib. As is your comment. > And it's the wrong lesson. It's only the wrong lesson if you believe that making it more difficult for governments to seize and decrypt their own citizens' mobile phones with impunity is not a valid goal. > the security model for trusted hardware is intrinsically flawed. It's only intrinsically flawed if you expect absolute perfection. The fact that some math-based protections may be theoretically better than physical protections does not obviate the utility of physical protections, whether we are discussing computers or phones, or houses or cars. It has been accepted since before any of us were born that there is no such thing as perfect physical security. Even your putative perfect cryptographic security still relies on the physical security of the plant holding the keys.
- 14d ago
- akoboldfrying 14d agoImpressive work! I have a side question. I looked into the linked Raspberry Pi hacking challenge, and there's something very basic I couldn't figure out: It looks like the relevant script in the repo just writes 0xc0ff 0xffee a few times to the OTP as the "secret" to unlock. But given that $20000 was up for grabs, this can't possibly be the genuine secret being sought to claim the prize. (Indeed, I can't think of a secure way to install a secret from a public GitHub repo unless it involves running on-device code that encrypts something using some other, factory-installed secret key, which is just kicking the can down the road.) And given that the OTP on a brand new RP23550 is initialised to all zeros, it can't be that the genuine secret is programmed in at the factory either. What am I missing? How does the genuine secret get installed on a person's RP2350?
- striking 14d ago> If you think you have found a break email us at doh@raspberrypi.com with details - we will ship you a Pico2 with a custom secret hidden in it. If you manage to extract it, you win the $20,000!
- akoboldfrying 14d agoThank you, don't know how I missed that!
- rkagerer 14d agoThe RP2350 is Raspberry Pi’s dual-core microcontroller: each processor socket can select either an Arm Cortex-M33 or a RISC-V Hazard3 core at boot. Does that mean there are four cores on the die? Is there crazy amounts of MUXing going on? Does the extra, semi-unused area give the chip a premium price tag? Or did I misinterpret this?
- raphlinus 14d agoYes, four cores in the chip. And yes, there's additional muxing, but I think that adds a fairly small amount of chip area compared with the crossbar. In addition to the two core slots, there are a lot of peripherals contending for single cycle bus access.
- LukeShu 14d ago> a premium price tag? $0.80 in bulk. Around $1.25 for individual quantities, depending on who your reseller is. AIUI, the CPU cores are a small fraction of the die area compared to all the peripherals on the chip.
- crote 13d agoYup, four cores. No crazy muxing needed because only one kind is ever active at a time and the other kind kept in reset, so there's no need to do any runtime arbitration - basically just a dumb switch on few dozen signals. The bonus RISC-V cores take up basically zero additional die space: for the RP2350 the lower size bound is the space needed at the periphery for connections to the outside world, and (unlike something like SRAM and analog IP blocks) logic is not too difficult to rearrange or even compress. This is the kind of thing that tends to start as an engineer joking about having enough spare space to fit in their toy RISC-V core, and then actually doing it. Run out of space during development? Just delete it, it's only an unexpected bonus feature after all. It causes issues during testing? Permanently fuse it off and nobody will notice it was ever there. High-end chips are filled with dozens of "chicken bits" to gate off functionality they might not be able to get to work properly, so in a small company like Raspberry Pi it probably wouldn't be too hard to convince management to take the tiny additional risk in return for a significant PR possibility.
- nullc 14d agoI'm confused by a number of comments here and the article seemingly taking a position that a $250k lab instrument is required. For one a similar instrument can be constructed from surplus parts for far less. Secondly, it's a single bit flip required. Now knowing the the technique works, a harness could be built that attempts it scattershot without the precise targeting and just has to try a lot of times. Using a different stimulus, e.g. xray it might well be possible without deencapsulating the part.