Live data from Hacker News

Attacking Titan M with Only One Byte

blog.quarkslab.com

11–20 of 84 posts

Re: Attacking Titan M with Only One Byte

#12
post #5

Earlier quoted context omitted.

Myself pulled in hoping for a historical tale of attacking vulnerabilities in Titan ICBMs.

Just curious - if the usage of acronym here a soft-euphemism? (So that only those who knew or care to know gets it) edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons: 1. Discussing "nukes" openly where I come from would raise some eyebrows. 2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.

ICBM is a very common term. For example, the NY Times uses it in headlines. https://www.nytimes.com/2022/05/24/world/asia/north-korea-ba...

Re: Attacking Titan M with Only One Byte

#13
I'm very happy to see that a vulnerability introduced in a May 2022 was found, diagnosed, and fixed in a June 2022 update.

After something went wrong, a bunch of things went right very quickly. Nice to have good news on a Monday morning.

Re: Attacking Titan M with Only One Byte

#15

Earlier quoted context omitted.

Just curious - if the usage of acronym here a soft-euphemism? (So that only those who knew or care to know gets it) edit: Thanks for the clarifications. That helps. I'm asking for 2 reasons: 1. Discussing "nukes" openly where I come from would raise some eyebrows. 2. I see acronyms used on HN frequently - sometimes ambiguously even considering the context.

I don't think so, people could just say "nukes" but there are plenty of nukes that aren't capable of hitting targets halfway around the world. ICBM seems like the fastest way of saying "nukes that can hit stuff really far away" while also making a distinction from sub launched and cruise missile launched nukes.

The payload on the missile doesn't need to be a nuclear weapon of any sort. The important thing about the ICBM is that being further away doesn't stop it. Nuclear weapons are the obvious choice because it's hard to imagine why you want to strike something so very far away, at such great expense, with conventional explosives.

The German V2 rocket from World War II has a maximum range of about 320km. So you literally can't fire one from say Berlin to London. They were actually launched from coastal sites in the Netherlands and other occupied countries, and as the Allies took territory after Overlord, the targets changed to cities nearer Germany because the launchers were pulled back.

Re: Attacking Titan M with Only One Byte

#16

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

Those committee's just lost contact to the real world. Ridiculous

Re: Attacking Titan M with Only One Byte

#17

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

i would imagine higher bounty would be for extracting device keys. from my reading this exploit would not allow you to extract the key needed to unlock a powered off device. im no security expert so please correct me if im wrong

Re: Attacking Titan M with Only One Byte

#18
post #8

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

Remote 0-day onto all google internal infra?

thats literally worth billions, and could be sold to many governments.

If thr right people don't buy these zero-days, yhe wrong people will.

Re: Attacking Titan M with Only One Byte

#19
post #16

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

Those committee's just lost contact to the real world. Ridiculous

I guess there's someone who orders the marketing department to say "1 million", while telling the operational side "10k", because his bonus rides on it.

Re: Attacking Titan M with Only One Byte

#20

This is an elegant attack that effectively compromises all Titan M chips. They were even able to dump all securely stored private cryptographic keys, which Google acknowledges in the disclosure timeline. Even still though, the award Google initially gave was only $10k USD(!). They finally bumped it to $75k USD after complaint and review, but Google's bug bounty program claims up to $1 Million USD. If fully compromisi…

> Really, what would, in the mind of those on the internal committee, constitute justification for the $1 Million bounty?

Probably something that doesn't require physical access to a key for longer time to extract the keys?

Post reply on HN