logoalt Hacker News

bob1029yesterday at 7:05 PM5 repliesview on HN

There are HSMs that are effectively immune to this attack by way of their construction and packaging. You need an optical path to the secure device. The only way to get at this is to tamper with the tamperproof part of the system.

Some very high end HSMs must be actively powered at all times which makes disturbances in their local environments detectable at all times as well. Getting lucky and drilling through a part of the enclosure that isn't directly protected won't help you if a barometric pressure sensor is tripped as a consequence of breaking the hermetic seal.


Replies

yndoendoyesterday at 9:25 PM

It sounds like a more cleaner method to obtain the keys versus using solvents and a lot of trial and error hardware. As described by Chris Gerlinsky with "How Do I Crack Satellite and Cable Pay TV?" [0] [1]

[0] https://simkl.com/tv/33956/chaos-communication-congress/seas...

[1] https://media.ccc.de/v/33c3-8127-how_do_i_crack_satellite_an...

palmoteayesterday at 7:12 PM

> Getting lucky and drilling through a part of the enclosure that isn't directly protected won't help you if a barometric pressure sensor is tripped as a consequence of breaking the hermetic seal.

That's interesting. I suppose if that technology is in use, the attack would have to occur in a pressure-controlled chamber, so breaking the seal wouldn't cause a change in pressure.

show 2 replies
bigiaintoday at 2:45 AM

Your phone isn't going to have a "very high end HSM" any time soon. n Not until you're paying mid range car prices or more for your very specialised secure phone (and then that phone will probably be factory backdoored AN0M-style).

stickfigureyesterday at 8:12 PM

Are any of these tamper-proof chips in my phone or laptop?

show 1 reply
EvanAndersonyesterday at 8:04 PM

> You need an optical path to the secure device.

Any path can be made into an optical path with a bright enough light. >smile<