Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
streaming.media.ccc.de
Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
1–10 of 25 posts
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#2Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#3Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#4Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#5Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
But I don't think that "targeting the education market" is accurate in the first place. They certainly make sure to serve that market with their very nicely priced Pico boards but it hardly seems to be their only goal. You don't go through the effort of spinning up a new revision to fix security holes if there aren't at least some industry customers.
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#6Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#7They'd prefer to live in ignorance.
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#8Seems a bit of a strange feature to even want on a product targeting the education market. In a classroom setting you don't really want students to be able to set fuse bits so the device can't be re-programmed. Presumably this is a sign RPi are deliberately aiming to straddle the hobby and light commercial markets?
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#9The “read the data out with a super expensive microscope” remained. Is there any way to defeat that attack I wonder? I suppose the hsm model of “destructive tamper detection” is one way.
Re: Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot
#10What an interesting talk, and an interesting concept also. Open source hardware security; get the security researchers interested and fix the security defects. The “read the data out with a super expensive microscope” remained. Is there any way to defeat that attack I wonder? I suppose the hsm model of “destructive tamper detection” is one way.