Live data from Hacker News

Attacking Titan M with Only One Byte

blog.quarkslab.com

81–84 of 84 posts

Re: Attacking Titan M with Only One Byte

#81
post #77

Earlier quoted context omitted.

Again this additional step slows down an attack which discourages people from attacking the product. If it achieves this it's a valid step as part of a security strategy. No single solution/step is 100% secure, if you think that, throw your devices away now because they're probably already compromised. Stop with the ego pedaling security stuff and live/work in the real world where small changes have real positive imp…

Sometimes, idiotic moves like that DRAW people to your product who'd otherwise pass it by. The only reason cypress got publicly embarrassed by their secure rom being completely broken [1] was because the way they talked about it annoyed me. [1] http://dmitry.gr/?r=05.Projects&proj=23.%20PSoC4

I...

Please stop arguing against a step which could have been taken as part of a valid security model...

I'm not saying this would have magically fixed the chip firmware. I'm not saying this would have magically stopped anyone ever getting into the device. I'm not saying this would stop Google accidentally shipping an unprovisioned unit.

I am saying a small move that strengthens the whole unit should be strongly considered. I'm sorry that backtracking from such a flippant response is so difficult for you.

Frankly it's a custom chip design, they could burn an efuse to cripple UART in production consumer units, that has the same effect for 99.99% of chips that would sell.

Re: Attacking Titan M with Only One Byte

#83

Earlier quoted context omitted.

Yeah some devices support PAC use that feature to sign return pointers. But not everyone uses it (even when available), and there exist methods to bypass PAC— from attacking the micro architecture to finding signing oracles.

PAC (pointer signing) & Branch Target Identification are not available on 32 bit arm chips, and judging by the assembly in the blog post the Titan M is a 32 bit chip.

There's a new PAC specification for ARMv8-M: https://community.arm.com/arm-community-blogs/b/architecture...

Re: Attacking Titan M with Only One Byte

#84

Earlier quoted context omitted.

thats literally worth billions, and could be sold to many governments. If thr right people don't buy these zero-days, yhe wrong people will.

Billions? couldn’t a government just get a person affiliated with them hired by google?

Most Google employees do not have direct access to all infra.
Post reply on HN