Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Cloudflare Quick Tunnels(cloudflare.com ↗)
    166comments
  2. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    22comments
  3. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    39comments
  4. North Korean nuclear test sets off years of earthquakes(science.org ↗)
    101comments
  5. US Military had close call after using AI for hallucinated intelligence report(cnn.com ↗)
    69comments
  6. OpenJev(openjev.com ↗)
    225comments
  7. C++26: Trivial infinite loops are no longer undefined behaviour(sandordargo.com ↗)
    128comments
  8. Systemd is a suite of basic building blocks(systemd.io ↗)
    17comments
  9. Show HN: Ax-check.com – Can agents use your product?(ax-check.com ↗)
    11comments
  10. I vibed a proof of Conway's conjecture(overreacted.io ↗)
    132comments
  11. A heap overflow and SSO misconfiguration to compromise OpenAI internal repos(hacktron.ai ↗)
    189comments
  12. Mathematicians Build Long-Awaited Graph Sandwich(quantamagazine.org ↗)
    10comments
  13. I don't like passkeys(hawksley.dev ↗)
    604comments
  14. Jemalloc 5.4.0(github.com/jemalloc ↗)
    77comments
  15. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss
  16. Border agents can search cellphones without a warrant or reasonable suspicion(lawandcrime.com ↗)
    12comments
  17. NATS publishes preliminary report on technical incident of 8 September(nats.aero ↗)
    24comments
  18. The scourge of x86 emulation(fex-emu.com ↗)
    71comments
  19. Show HN: Scry, programmable internet search w/ congestion pricing(scry.io ↗)
    8comments
  20. The Shadows Lurking in the Equations – Underwater Islands(gods.art ↗)
    13comments
  21. Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him(nytimes.com ↗)
    172comments
  22. GrassLobster: AI Agentic Generation of Parametric Geometry Workflows(miro.vision ↗)
    5comments
  23. BeanShell3 in Development(beanshell.github.io ↗)
    18comments
  24. Replacing Pull Requests with Delta(zed.dev ↗)
    80comments
  25. AI chatbots are becoming experts at changing people's minds(science.org ↗)
    83comments
  26. An empirical study of harness design for coding agents(arxiv.org ↗)
    49comments
  27. Bend 2 and the Vibe-Coding Trap(liampwll.com ↗)
    224comments
  28. Build Faster Feedback Loops Using Qualitative User Research(nseldeib.com ↗)
    2comments
  29. Pre-Greek: The lost language hidden within Ancient Greek(linguisticdiscovery.com ↗)
    63comments
  30. Microsoft exec called AI scraping 'the largest theft of labor in human history'(techcrunch.com ↗)
    685comments

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

74 pointsby 2h agodonjon.ledger.com
20 comments
1h agoHN ↗

The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

Not super practical, but neat attack

1h agoHN ↗

$250,000 of laboratory equipment

*currently

22m agoHN ↗

In 5 years, either $400,000 or $50 and a hammer, depending on whether the core piece of the process aligns with the needs of some fast-growing consumer tech product like e.g. drones.

1h agoHN ↗

Some people have such and other toys just at work and can use it in spare time.

1h agoHN ↗

250k is not a bad investment for a company doing "reverse engineering as a service" - say 1k a pop to extract the firmware. Naturally, a good business idea for somewhere in the world with less regulations...

48m agoHN ↗

That is peanuts for a nation-state actor.

32m agoHN ↗

Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.

19m agoHN ↗

The RP2350 is an inexpensive microcontroller IC with reasonable performance and some very useful (and somewhat unusual) features in its PIO blocks.

Why wouldn't a person build that into the heart of something important?

16m agoHN ↗

"Important" and "tamper proof against a determined adversary" are very different goals.

11m agoHN ↗

Sure, but if you’re defending against a nation state actor hopefully you aren’t expecting a raspberry pi to keep you secure.

Is there anything about these techniques that are raspberry pi specific? It seems like they're using lasers to identify and flip particular bits in registers.

44m agoHN ↗

It reads as impressive defense. Meaning that it's presumably not possible to get root with physical access on a live 50$ device without 250k capital

11m agoHN ↗

This is for a $1 microcontroller. I'm assuming you're talking about the Raspberry Pi computers based on the $50 cost and root.

1h agoHN ↗

It needs to be updated. Modern evil planners don't even need a wrench since they already have most keys given to them in advance by everyone, including nerds

1h agoHN ↗

That's reminiscent of when we first found out that if you opened up dram chips you could use them for imaging. Of course the scale at which this is done is extremely impressive.

43m agoHN ↗

Now it can be done for Apple iPhone. Apple is cooked.

7m agoHN ↗

I appreciate all the details they provide in the post. The $250k in lab gear is useful when initially discovering, exploiting and documenting attacks like this.

Definitely doable in a home lab for under $25k in equipment, likely under $10k.

Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).

https://youtu.be/URmI1VVilek