4 ms·
The LIFX guys should asap enable the lock bits on the micro conrollers. Reading out the firmware from a product is a no-go. The TI CC2538 should be safe agains
by cryo 12y ago
The LIFX guys should asap enable the lock bits on the micro conrollers. Reading out the firmware from a product is a no-go.
The TI CC2538 should be safe against attacks in which the flash could be obtained even after a chip erase like in older modules [1].
[1] TI CC2430 Attack http://www.blackhat.com/presentations/bh-usa-09/GOODSPEED/BHUSA09-Goodspeed-ZigbeeChips-PAPER.pdf http://www.blackhat.com/presentations/bh-usa-09/GOODSPEED/BH...
- e12e 12y agoThey're distributing the firmware on-line (for updates) -- why prevent reading the firmware from the chip itself?
- mschuster91 12y agoDistribute encrypted firmwares instead so that hackers have to first extract the (in this case globally distributed) private key.
- TeMPOraL 12y agoRuining the fun for everyone of us :(. Seriously, I dislike this trend of making everything a closed and encrypted black box accessible only through official channels (that will disappear in 3 years anyway) for reasons mostly related to money-making and not really security. I think this is will, if continued, slow down the rate of technological progress and development of new ideas. To quote pg, "It is by poking about inside current technology that hackers get ideas for the next generation. No thanks, intellectual homeowners may say, we don't need any outside help. But they're wrong. The next generation of computer technology has often—perhaps more often than not—been developed by outsiders." http://paulgraham.com/gba.html http://paulgraham.com/gba.html
- cryo 12y agoThe hacker in me totally agrees with that point of view. It would be awesome to have a chance to decompile firmware and analyse and hack the communication protocols. But then security is important (which is true for almost all wireless stuff), things are quite different. It's pretty hard to build embedded devices which provide basic means of security without having a poor user experience.
- e12e 12y agoIf the security of the system relies on the system be secret, as opposed to the keys being secret, the system isn't secure... As have been shown again and again, you can't give someone the code (obfuscated, compiled, encrypted along with the decryption key) and also not give them the code. So you'll slow down reversing, and probably deter most hobbyists -- but not anyone with anything tangible to gain from breaking your system. Personally I think "obviously insecure" is better than "might be somewhat safe".
- mschuster91 12y ago> Ruining the fun for everyone of us :(. Enough of us have more fun reversing or breaking crypto applications :)