3 ms·
> The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment. Not super practical, but neat attack
by stackghost 13d ago
> The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.
Not super practical, but neat attack
- mrlambchop 13d ago250k is not a bad investment for a company doing "reverse engineering as a service" - say 1k a pop to extract the firmware. Naturally, a good business idea for somewhere in the world with less regulations...
- paulnpace 13d ago> $250,000 of laboratory equipment *currently
- stavros 13d ago$300,000 next year.
- k12sosse 13d agoWe're already up to 400,000 just today.
- TeMPOraL 13d agoIn 5 years, either $400,000 or $50 and a hammer, depending on whether the core piece of the process aligns with the needs of some fast-growing consumer tech product like e.g. drones.
- dist-epoch 13d agoI think GP was making a joke about RAM prices. Makes me wonder what is the effect of the RAMpocalypse on drone prices.
- TeMPOraL 13d agoMaybe. I was referencing my own realization earlier today, when I was wondering if I can DYI a ground-penetrating radar to scan the allotment garden for hidden "surprises". A ground-penetrating radar is something I learned about as a kid watching a popular science videotape, back then a stupidly expensive high-tech piece of professional equipment. But it hit me that there are two main forces keeping such technologies stupidly expensive and inaccessible to general public over time: costs of knowledge that went into their design (protected by patents and trade secrets), and specialized parts made in unique way or from unique materials, that don't happen to have alternate applications. Nowadays, knowledge is not an issue - 20+ years is enough for all the relevant patents to expire, and information to have seeped through to the Internet, available in a combination of Wikipedia articles, textbooks, scientific papers, and blogs, plus we have good LLMs more than happy to synthesize that and transform into a DIY tutorial for dummies. Which leaves the parts. Whether or not you can DIY such a tech really hinges on whether you can find the critical components somewhere. If they're still unique, you're paying $$$ for procurement (and it makes more sense to try and score broken/used equipment off eBay or something). But there's a chance there's a close equivalent that's part of mass consumer or prosumer device, at which point you just buy it and strip it for parts. (Which way it is with ground-penetrating radars? Don't know, didn't bother to prompt an LLM with that question yet.)
- dist-epoch 13d ago[dead]
- MadnessASAP 13d agoRadar is cheap now, thanks to semiconductors getting smaller and faster the analog front-end which used to be a long expensive chain of components is now much smaller, the ADC is now faster, more accurate, and cheaper, the processor is now fast enough to keep up with a higher bandwidth signal. You could probably drive a very rough radar system directly off a Pico's GPIO and ADC, maybe toss in a decently fast op-amp for a receive amplifier. Where you will run into issues is processing radar signals into usable data. If you're happy with the results that radar was giving 30 years ago then it's fine and dandy, but the magic of modern radar is in the software, not the hardware.
- etdznots 12d agoLlms should make these cost even less im thinking $50 in 18 months?
- _trampeltier 13d agoSome people have such and other toys just at work and can use it in spare time.
- stickfigure 13d agoThat is peanuts for a nation-state actor.
- stackghost 13d agoSure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.
- ssl-3 13d agoThe RP2350 is an inexpensive microcontroller IC with reasonable performance and some very useful (and somewhat unusual) features in its PIO blocks. Why wouldn't a person build that into the heart of something important?
- sephamorr 13d ago"Important" and "tamper proof against a determined adversary" are very different goals.
- jacquesm 13d agoTamper proof against a determined adversary starts at 'call us' not at '$10'.
- stackghost 13d ago>Why wouldn't a person build that into the heart of something important? Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.
- rcxdude 13d agoRp2350s are advertised as having quite a few anti-tamper functions. They had a bounty when it launched to find similar vulnerabilities and they worked to patch the ones that were found. This is a lot more credible than a lot of advertised anti-tamper features.
- TZubiri 13d agoIt reads as impressive defense. Meaning that it's presumably not possible to get root with physical access on a live 50$ device without 250k capital
- Rohansi 13d agoThis is for a $1 microcontroller. I'm assuming you're talking about the Raspberry Pi computers based on the $50 cost and root.
- crote 12d agoIt's a $1 MCU, which will get embedded into a $50 device. If you're a company selling a cloud-plus-device product, then that 250k tooling cost and not-exactly-trivial attack process will be quite effective at stopping Chinese clones: with a unique per-device key there's no way they'll sell enough units to make a profit before you will inevitably ban their cloned key.
- TZubiri 11d agoWell not chinese clones, those are well funded factories with state su subsidies, but it will definitely stop rogue individual hackers. It's not even 250k cost, just 250k capital, it can be rented.