Hacker News new | past | comments | ask | show | jobs | submit login

Oh neat. That key extraction technique is very fun. Has anyone seen this this before in another major project?



Yes, the general flaw/technique is alarmingly common.

psvita: https://www.lolhax.org/2019/01/02/extracting-keys-f00d-crumb...

ps4: https://twitter.com/flat_z/status/1472243592815169546

nintendo switch (tegra X1): https://switchbrew.org/wiki/Switch_System_Flaws (see "Security Engine keyslots vulnerable to partial overwrite attack")

(Nintendo really ought to have known better, but I suppose the security of their alarm clock product isn't exactly a top priority - and given the hardware choice it was mostly out of their control anyway)


It is indeed a really cool key extraction method. The code is also written in such a straightforward way that it is easy to grasp what's going on.

Now I have to find some encrypted files to play with :D




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: