Live data from Hacker News

Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

streaming.media.ccc.de

1–10 of 25 posts

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#2
Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed.

Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#3
post #2

Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

They have absolutely been aiming at industrial customers already. It would be hard for them to justify the cost of a custom die without having some volume to businesses. (And the previous raspbarry pis have absolutely been popular in industry as well, I would be surprised if hobbyists and learners are even half of their volume)

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#4
post #2

Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

[deleted]

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#5
post #2

Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

If that's a concern, you can lock the OTP either permanently or with a password, before you hand them out. Or just use the older RP2040.

But I don't think that "targeting the education market" is accurate in the first place. They certainly make sure to serve that market with their very nicely priced Pico boards but it hardly seems to be their only goal. You don't go through the effort of spinning up a new revision to fix security holes if there aren't at least some industry customers.

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#6
post #2

Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

They have been serving enterprise markets for a long time. Back in 2020-2021 when there was a chip shortage, Raspberry Pi shorted their consumer availability to make sure enterprise customers could still get compute modules. The fusible bits on the RP2350 are very much an enterprise feature.

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#8
post #2

Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?

Are you perhaps confusing the Raspberry Pi Foundation with the Raspberry Pi Holdings?

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#9
What an interesting talk, and an interesting concept also. Open source hardware security; get the security researchers interested and fix the security defects.

The “read the data out with a super expensive microscope” remained. Is there any way to defeat that attack I wonder? I suppose the hsm model of “destructive tamper detection” is one way.

Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot

#10

What an interesting talk, and an interesting concept also. Open source hardware security; get the security researchers interested and fix the security defects. The “read the data out with a super expensive microscope” remained. Is there any way to defeat that attack I wonder? I suppose the hsm model of “destructive tamper detection” is one way.

I patented something that had a countermeasure for this, which was a bit impractical but fun to think about. Basically you put the sensitive data in an eeprom layered with a chemical that emits UV when exposed to air or, optionally, visible light - chemically more entertaining, hard to manufacture. But it's a just an arms race at that point.
Post reply on HN