Manual chip decapsulation [video]
duo.com
duo.com
Like another commenter said, I found that the video is contained in an <iframe> so I grabbed its URL and found it works nicely to watch the video in a separate window or browser tab. :)
I searched around to see if the video host ("Wistia") displays videos in some more YouTube-like layout, but it seems not.
See also this talk from Defcon 21: https://www.youtube.com/watch?v=7Q82FkthDx8
And this write up for dumping the firmware from the PIC 18F1320 by masking half the chip and exposing the other half to UV light: https://www.bunniestudios.com/blog/?page_id=40
This is a pretty old technique. Almost every modern produce chip has mitigations for UV erasing.
What is the benefit in selectively erasing part of the chip? How does that help you read the part that isn't erased?
So imagine your flash is over here, and your SRAM is over here, and over on this other side is the SFRs and inside those are bits that once set disable the debug interface. Reset just those and you can dump the firmware.
Often you blow fuses in multiples and take a vote, because the fuses can occasionally re-connect or have awkward leakage due to how the metal bits behaved during the over-current, and that's embarrassing for a fuse controlling a security feature.
(I’m a software guy though, so this is all outside my area.)
More modern chips just have metal layers over the flash. You can decap and have a layer of transistors or a layer of metal or some other impediment to the UV light.
Well this guy may have figured out another way to decap chips, this is not a (great) way to hack chips anymore.
"Direct" tampering with hardware is always possible, but for a recent design it will be extraordinarily expensive--electron microscopes, FIB, and so on. The interesting exploits are usually mistakes in the logic, the power supply sequencing, etc., not direct attacks on the memory cell. There's maybe some analogy with software security, where practical attacks on a (well-known) crypto algorithm are incredibly rare, and practical attacks on everything around it are incredibly common.
In principle you can uncap the chip and get that key back out. You could then clone it, or bypass any restrictions built into the chip like "I won't authorise more than £200 total spend without going online". I'm not sure how that would be worth doing unless it's surprisingly easy and quick.
Unlike with cloning magstripe cards though this would trash the original, take substantially more than a couple of minutes and be readily detectable by the issuing bank if they are paying attention. So it seems crazy to me and my default position would be to believe it's not actually being done, certainly on an "industrial" scale.
So, even when a card is does not arrive, most people will assume that the post simply lost it, and call for another replacement.
As I understand, a great lot of banks still ship fully active cards that require no "activation" by phone or online, assuming that nobody can recover the pin.
Is the actual pin on the chip though? I would have assumed only a hash of it was stored, enough that it can verify the right pin has been supplied without having to store the actual code?
Rainbow tables make no sense here, the rainbow table is a clever optimisation of the normal time-space tradeoff where we don't want to pay the full space cost, and will accept a time penalty (and usually in practice an accuracy penalty) to avoid using so much space.
For a four digit PIN there is no concern about space, storing and indexing 10 000 possible hashes is trivial, (whereas storing and indexing say three trillion password hashes is kind of a pain so that's why you have rainbow tables)
"More security-focused mircocontrollers like the ones used in hardware security modules (HSM) to store encryption keys, trusted platform modules (TPM), and SIM-cards have have hardened chipsets to make these invasive attacks more challenging, Davidov said. They have countermeasures such as protective shielding and an active mesh layer to detect when a trace has been cut. Light sensors, when tripped, could automatically destroy all stored secrets if the chip powered on after the molding component was removed. While there are ways to bypass these features, they require extremely specialized equipment and 'significant investment.'"[1]
[1] https://duo.com/decipher/new-diy-method-researchers-recover-...
The problem with that is, there are fewer people capable of attacking their countermeasures and so they don't get a strong test before being deployed. I'll always remember Christopher Tarnovsky's talks at DEFCON.