4 ms·
tl;dr "By holding down the single button, while powering the device, the Chromecast boots into USB boot mode. USB boot mode looks for a signed image at 0×1000
by SpikedCola 13y ago
tl;dr
"By holding down the single button, while powering the device, the Chromecast boots into USB boot mode. USB boot mode looks for a signed image at 0×1000 on the USB drive. When found, the image is passed to the internal crypto hardware to be verified, but after this process the return code is never checked! Therefore, we can execute any code at will."
That's a pretty big screw-up on someone's part - it seems strange that no one tested "does this unsigned image boot".
- oakwhiz 13y agoIt's amusing, and perhaps a bit distressing, that all the work put into using hardware crypto was defeated by such a simple failure like that.
- hrkristian 13y agoOne will never know if it might've been done on purpose.
- ZoF 13y agoHard to call seemingly advertent actions a failure...
- jonknee 13y agoI'll avoid judgement for a big "screw-up" that lets someone who run what they want on a device they purchased.
- GravityWell 13y agoRight, "holding down the single button" certainly means the user has physical access, so this sounds like it is by design. There is context to security.
- randallu 13y agoProbably the Marvell first-stage bootloader always verifies what it loads and the decision of whether to enforce or not comes after verification. Google chose not to enforce, good for us :).
- duskwuff 13y agoSimilar in this respect to several Chumby devices (esp. the Chumby 8) which used SoCs with hardware signing, but chose to either disable it or use it in as minimal a fashion as possible.
- achamayou 13y agoOr perhaps it was done exactly for that reason : it made testing easier, and they just forgot to turn the check back on before shipping ?
- dpeck 13y agoScrew up, or perhaps the engineers understood how many of the people like themselves would want to use it.
- bigiain 13y agoPerhaps not just the engineers either. I'm working with these people: http://dev.moorescloud.com/ http://dev.moorescloud.com/ Check out the text on the pcb mask just between the bottom row of pads and the microSD card here: http://dev.moorescloud.com/wp-content/uploads/2013/07/Holiday-PCB-front.jpg http://dev.moorescloud.com/wp-content/uploads/2013/07/Holida... We're going to a lot of effort to ensure these are "secure" for regular users – but it's an iMX233 ARM Linux device with a ATmega328 "Arduino" hanging off it – it's eminently hackable, and at least at the current introductory price it's very cost effective compared to, say, a RaspberryPi with a power-supply/case/wifi-adapter/Arduino (which is almost exactly what the prototype was). While we're working hard to ensure your Christmas tree lights aren't remotely exploitable – if you've got it in your hands and have a screwdriver handy – it's yours to do what you want with. You can pop that SD card out and load your own OS to play with the software, and you've got a bunch of GPIO pins from both the iMX233 and the ATmega328 if you want to play with the hardware. I'll be a little disappointed if no-one's got one controlling a quadcopter or a laser cutter or a 3d printer within a few weeks of them shipping…
- laureny 13y agoGoogle has a strong history of not locking up devices in beta (and often, not even locking up released products either). I very much doubt it's a screw up.
- bigiain 13y agoSounds quite likely that even if the return code checking does get patched in, that this will still be vulnerable to Travis Goodspeed's techniques here: https://www.youtube.com/watch?v=ijyAwxH_iok https://www.youtube.com/watch?v=ijyAwxH_iok (So you don't ned to watch right through – though I highly recommend you do – there's a trick he describes where you use a specially crafted "USB Drive" which can return one version of a file the first time it's read, and a different file the second time – if you know you've got a device that reads in a file to check it's signature first, then reads it again assuming it's getting the same content – that assumption isn't necessarily correct… A "smart" USB Drive can return whatever you choose, including a properly signed Google sourced image the first time 0x1000 is read, and whatever else you want the second time when the device is mounting it rather than verifying it.)
- jevinskie 13y agoThe original PS3 jailbreak used a similar trick where the first USB descriptor returned had size A and the second time the descriptor was read it was size B > A. Buffer overrun! =) It required a special device that can act as a USB gadget like a Nokia N900 or AVR-USB micro.
- bigiain 13y agoYeah, Travis credits that with the inspiration for some of his work in the presentation.