Full key extraction of Nvidia TSEC
gist.githubusercontent.com
gist.githubusercontent.com
I've done some reversing when I was younger, cracked some software and hardware locks, there's nothing as exhilarating as breaking through something that looked impossible. Well done!
Here's a video of someone finally cracking into the Sega Saturn well after the console was current commodity: https://www.youtube.com/watch?v=jOyfZex7B3E&t=202s
For those unfamiliar, the Satiator is an adapter of sorts that lets you load Saturn ISOs onto an SD card and play them via the Saturn's MPEG adapter slot.
Unlike many solutions on various consoles that bypass the optical drive, no hardware modifications are required. Your Saturn stays intact; it's truly plug-and-play.
This sort of thing is important. Consoles (specifically moving parts, like the optical drives) and physical media from the 90s are failing. Surviving consoles and games can be quite expensive; even thousands of dollars. Emulation is imperfect and introduces lag. Satiator and other flashcarts let us play these games on original hardware and bypass these issues.
Wouldn't the original firmware need code to boot from SD? Maybe it automatically checks for new firmware on the card and then gets exploited from there? Does anyone know?
"This is how cool I am. I have cracked it before everybody else."
They're positioned on the complete opposite of the modern corporate, capitalist Internet, keeping computers open and still cool. For that, I salute them.
By publishing the exploit they lose any market advantage.
In the "bad old days," you could make a moderate (nothing like Silicon Valley engineer money) sum by selling exploits to modchip manufacturers, as they'd then use this to drive their hardware sales - pretty simple model. The last one of these I remember being particularly popular was the PS3 "True Blue" dongle.
These days, exploits aren't particularly useful to drive hardware sales as they're mostly hardware free. So there's not a ton of monetary value - yes, you could try to sell a "custom firmware" for a few months, but once the exploit is reversed, it's game over for your income stream.
Cheating is probably the only major revenue stream left in console exploitation, and as far as I know it's not popular enough to drive high prices for console exploits. Compared to phone exploits (wanted by nation-level actors and shady security firms for mostly evil purposes), ECU exploits (easier to protect and worth more per install), and PC exploit bug bounties, I think console hacking is pretty low on the lucrative scale, which is why so much more of it is done in the open.
Also, to succeed as a streamer you have to stream ~40 hours a week or more, and there's something called "aim fatigue". After an hour or so without breaks, your aim goes downhill. Anyone who maintains amazing aim for hours of continuous play is cheating. That's why you see experienced, successful streamers taking breaks, or interspersing "hang out time" or a non-aim-based game, etc.
Stream framerates / compression can make it difficult to tell what's going on, and using a controller means it's nearly impossible to see whether their controller movement matches on-screen movement. But controller aim assist is so strong in many games these days that if you have experience with a controller you can easily dominate all but the top mouse and keyboard players.
Shooting-based games just aren't fun these days. Between the cheaters and the streamers you get your ass handed to you pretty regularly, except when matchmaking throws you an easy game to keep you from rage-quitting.
Man, that's so weird to see.
I've always been told by fellow gamers that a keyboard and mouse is the competitive option, while controllers are for the less experienced.
There was a thread on HN about this the other day - at the most advanced end, bus mastering DMA devices are used to dump game memory for direct inspection, or to recover ephemeral / session negotiated keys used to secure client<->server traffic, and then dump or inject network traffic on a separate machine. PCIe FPGA cards are the most popular tool for this, but there are other approaches given anything with DMA mastering can be employed to sneak data out without the OS or user land knowing much about it.
There's also a big middle ground which is just a software cat and mouse game between detectability and effect - just like antivirus, anti-cheat is an uphill battle on machines where users can run whatever code they'd like.
Many of these cheating services are subscription based so they're pretty lucrative for the authors.
But, I'm not aware of as much (or really, any) of this going on in the console space. There aren't that many competitive console streamers to start with, and console eSports events generally use tournament-provided hardware. So, the possible revenue stream doesn't really reach the massive undertaking that would be required to break modern console security on anything but the Switch.
The drive would report via some “secure” firmware if the disc passed detection or not. So the hackers made a firmware that reported good on a failure, ways to flash the drives over SATA, etc.
But either Microsoft was very clever or the hackers made a mistake… the drive would report the angle of the disc during certain movements. It would do some operation and report it went from 20degrees to 223 degrees. Well, the hackers and MS disagreed on an angle integer rollover.
The original drive would report 0-359degrees, but the hacked drive rolled over different and reported 0-360degrees or vice versa, I don’t remember. So iirc, MS listened for awhile, if a drive ever reported 360 degrees or whatever the wrong indication was, MS added it to a list.
One day, the drop the hammer banned the lot of them. It took the hackers awhile to figure out how they were getting caught. In the meantime, I now had an Offline-Only 360.
I can really recommend this, if only as a cautionary tale against password reuse.
https://www.youtube.com/watch?v=eviSykqSUUw
The core of it is a respectably sophisticated LOD building algorithm, as you might expect, but the sheer amount of engineering horsepower they put into driving it into production just boggles the mind.
Guarding Against Physical Attacks: The Xbox One Story — Tony Chen, Microsoft - https://www.youtube.com/watch?v=U7VwtOrwceo
Discussion: https://news.ycombinator.com/item?id=21325421
I wonder if it will be mitigated by requiring a larger minimum voltage?
[0] https://en.wikipedia.org/wiki/Differential_fault_analysis
How would you detect low voltage without a reference voltage?
(Also, temperature sensors. Sheesh people.)
It's the basis of how DirecTV cards were compromised in the late 90s/early 00s.
The best video about it that I've seen is from 33c3 https://youtu.be/lhbSD1Jba0Q
He bought a carful of cable boxes and glitched them into submission using a NOP slide and custom code to extract the firmware, IIRC over I2C.
It was an awesome talk and really explained it well!!
Has anyone ever hacked DishNetwork/Echostar/Nagravision cards? 10+ years ago I was fascinated to learn about how the new at the time "Nagra3" cards worked so well. I never did find out how those things worked as they seemed impossible to break. I also vaguely remember the story of how Directv owners (owners of FOX networks) secretly commissioned some hackers in Israel to crack their competitors systems while at the same time securing their system further. They eventually got sued but paid a pittance in restitution while their competitors suffered serious financial issues. Really unethical behavior.
It wasn't much of a secret.
Newscorp (the FOX assholes) didn't control DTV until 2003. Prior to that, however, DTV utilized the services of NDS for security.
NDS was owned by Newscorp, and run by ex-mossad hackers. For some strange reason DTV was constantly owned again and again while NDS was responsible for security at DTV.
In 2002, DTV rolled out a new access card without the involvement of NDS, and by golly, it was secure (and remained secure for years).
In 2003, Newscorp said fuck that, and bought a controlling interest in DTV.
The problem is that this doesn't work for high performance CPUs, so it can only really be done for things like TSEC or Apple's SEP. You need the CPU to have a large margin where it operates correctly, so the sensor doesn't have to be extremely fast and accurate (which is nigh impossible with on-chip sensors with no external reference). And even then it has to be able to detect things like microsecond-long dips in the supply voltage, or extreme temperatures, or a single clock pulse that's too short. It's really hard.
Several years ago, I got the Wii U PowerPC boot ROM keys out by doing a self contained glitching attack like this. In that case it was a reset glitch, where I pulsed the reset line for less than the required 256 clock cycles (from the ARM core which controls it). At very specific pulse widths (that varied from device to device), that got the CPU into an inconsistent execution state that eventually fell out of the Boot ROM and into code I'd placed in RAM. That one could've easily been mitigated by a reset stretcher circuit, but it's another fun example of a "self-glitch" attack with no additional hardware.
Congrats to them !
Errr, no. Just because you would have more details and everything would seem easier to understand and it's simple to sit on the couch and be like "yeah that looks simple, I could have done that", because that still glosses over the huge amount of research and the number of trails and errors the author put in not just during this project but throughout his career to get to this point where everything Just Works™ for him so he can make it look simple for everyone else.
Just like with Edison and the light bulb, even if the end result seems very simple in hindsight, the process of getting there is definitely not.
(Feynman said something like, if you can't explain it to a layman you don't really understand it.)
After all, all this genius did is open a nintendo switch to eventually run software made by you for free. The contrary of productive work I d say and close to parasitism.
Or so you can tell yourself when you feel down :D
I think the situation about voting is summarized pretty well by this funny rap clip form the 2016 USA elections: https://yewtu.be/watch?v=D9Qv6S_GtLo
Boston Tea Party, Union strikes/riots, guillotine.
Oligarchs slow boil the proles until they pop.
For example, an oncologist is not expected to have the same understanding of bacteria as a microbiologist and they aren't an impostor for not knowing.
But I feel you, whenever I read the more technical posts on HN I feel the same way.
Because it comes from that special perspective of being able to xray through the entire stack, all the way down the physics of the electronics driving the thing while keeping the context of all the other layers in mind to see how different parts can be manipulated to get the results you want. I get the most enjoyment out of my work when doing this with higher level layers, but being able to do it at the hardware end must feel exhilarating, because that's really how it all works.
I find that it helps if you start with things like 8-bit microcontrollers where you're writing C code or even assembly language, yet it's simple enough to wrap your head around easily (make sure you hit the metal; a lot of people doing this start off with Arduino and get stuck with the high level libraries, but then you're not really learning anything about how it works). Then if you know a bit about digital logic, it's not hard to learn how such an 8-bit CPU might be designed. At that point you can shift to larger and larger systems while still being able to "connect the dots" from a GUI app down to NAND gates. Of course you won't know the details of the whole stack (nobody does), but you'll have enough of a big picture overview to be able to dig your way through it when it becomes necessary.
To add one cent: most of us have to be "productive" in a sense that requires us to use a LOT of abstractions.
The author went the other way, understanding how things work under the hood in quite a deep level.
It's truly awesome, but you also have to appreciate how abstractions have their place in modern software dev industry.
Also, apparently the Switch perma-pwn got pwned? Sad face...
Also also, I hope other popular cryptoprocessors aren't so vulnerable?
All erista units (the ones with the bootrom flaw) are still pwnable.
6.2.0 was released on November 19, 2018 - first indication of a new hack was posted on twitter Nov 24, 2018 by @elmirorac and atmosphere 0.8.0 was released on Nov 29, 2018. So the fix he talks about in the paste lasted for around 10 days before a new one was generally available.
That's why he says:
> And it would have been perfect if not for the many security flaws in TSEC secure boot.
You might be surprised, but also this chip wasn't intended to be used to secure a chain of trust but had to be press ganged into service after being let down by the main bootrom, which was done by a team at NVidia without much experience of doing these things and made a lot of elementary errors. And being used for a games console is painting a big target on your back.
But ultimately a lot of secure chipset areas have been subject to a lot of... learning on the job shall we say. Things are much better than they used to be, but you don't have to go back many years before things get very hairy. People constantly say they want more OS version support for Android, but I would not want to use a five year old processor from Samsung or Qualcomm if I cared about the hardware backed security on my phone.
What I would really like is a modern Android that doesn't brick half the security features by e-fuse when I root it and many apps refuse to run properly afterwards - why the fuck, for example, does the PayPal app refuse fingerprint unlocking after rooting but other apps don't?! All this incentivizes me as the user is to choose an insecure password that I can actually remember.
OnePlus does not do this.
For the NV TSEC-equivalent Falcon successor on Ampere, it’s indeed not vulnerable to this attack because that security subsystem was made much more secure.
But that’s an arch released in… 2020.
> (2) its own "secure boot"
As soon as you see the quotes, you know what's coming! It's like Chekhov's gun :)
>Because this is a (unmitigable!) hardware issue in all Falcons which have SCP, not just TSEC -- we were also able to use the same attack on the Falcon unit used for GPU power management, recovering its (different) signing key as well.
In short, the same methodology, assuming you put a crap ton of time into reading this, and really grokking it, suggests this attack could be applied not just to Tegra, but any secretful Falcon.
From a design perspective, this is why you don't have your entire ecosystem depend on a shared secret stored in secure hardware, even if they're written when the chip is still in the flasher at the fab. You need either to diversify your keys in the flasher, or do an initialization/personalization protocol to update the keys to new unique per-console ones so that a crack like this isn't portable across every other customer device. As a design consideration, it means the customer has to be online to personalize the device to get their unique keys, but that's the trade off.
The beauty of demonstrating this attack is that if you think game consoles with security modules are vulnerable to having ecosystem compromising shared secrets extracted, wait until you see phones.
then, seeing all console video games in "bargain bins" for $1-$2 each and even then extremely few people were buying them. I recall seeing bins going virtually untouched for months.
parents just stopped buying games for their kids' consoles, nearly completely. the idea of a home video game console was so negative that Nintendo needed to call the NES an Entertainment System in order to get their device into homes. That Nintendo Seal of Quality really meant something, and only Nintendo could manufacture the lockout chip that prevented unauthorized games from running, so that Seal of Quality really had weight and it basically meant "no shovelware games" for it's entire existence.
Entrepreneurs showed Nintendo and Atari what happens when you have no console security: that lots and lots of people will eagerly crush the entire market in exchange for a bit of money. Nintendo has not forgotten this lesson, and they're not likely to.
If the reason for people buying shovelware is that they need to go home and try it to see if it’s bad, wouldn’t a simple blank CD packaged as a game achieve the same thing?
even with the NES CIC chip keeping most unauthorized games from working, Atari successfully duplicated the functionality of the chip and published their own games under the "Tengen" brand. Nintendo was very unhappy about this, and while Nintendo won in court, they learned their lesson and doubled-down on console protections from then on.
Nintendo are unlikely to ever forget the lesson that this court case taught them.
So, with that, even with the presence of technological measures to keep non-nintendo-made carts out of the NES, there were still non-nintendo games running inside NES consoles.
things like this are why Nintendo, Microsoft, and Sony are so dedicated to locking the consoles down and doing everything they can to prevent unauthorized access. Nintendo has been shown multiple times that companies will just do whatever they want unless there are strong lockdown features to the hardware.
others have learned from Nintendo's experience, as well, and that's why we are where we are today. we will not be returning to the early days of video game consoles, where hardware was unprotected.
From Nintendo’s perspective, locked hardware makes sense. They risk being locked out of profits from other publishers.
However, I’m not convinced that’s the case from a consumer perspective. The reason you gave in the original comment was that consumers suffered from the open platform. I still disagree with that. Consumers suffered because the platform was open AND there was no trusted source for quality control. You don’t have to take away 1) for consumers to not accidentally get terrible games, you just have to have a trusted source which tells consumers which games are good so that 2) isn’t the case. As soon as consumers know they can buy good games directly from Nintendo (or from blessed retailers), the onus for running crapware is on them.
Nintendo won't even sell development kits for the Switch to just anyone. you have to have a "good enough" game pitch (with no published rules on what is good enough and what is not) and you must commit to actually producing the game before they will even let you SEE the development kit and related items in the developer account store.
of course you can buy dev kits for the Wii U and 3DS, the discontinued systems, but you can't produce software that runs on the retail hardware, even for those.
Steam theoretically can control quality as much as they want. The bar they choose is entirely arbitrary and completely upto them.
What about the bit flips allows the key to be solved for? That is the part of this I don't understand
I've done the same thing to break "white-box" AES implementations, which are software versions of AES with the algorithm obfuscated and the key baked into it, in the form of flattened per-round-byte lookup tables (this concept is complete snake oil, but a few companies insist on selling it; they claim it's hard or impossible to get the key out, but this method works every time). You can introduce faults by patching the code or using a debugger to change state in the last round or two, and compute the key from the results. I did a targeted attack where I surgically introduced faults by replacing intermediate values with ones from a different input (which works even when the algorithm uses redundant, booby trapped encodings, which is another feature these vendors peddle), but in most cases you can also just literally randomly corrupt execution and use the same script Yifanlu wrote, just like a random hardware glitching attack.
And regularly get their card security schemes busted.
The advantage that smartcards currently have is that not many people are looking into their security outside of pay-TV pirates. Phone users don't have a need to hack their own SIM cards, friends of OpenBTS simply use blank SIM cards, bank users don't need to hack their own cards, and card cloners have a hard time getting physical access to the chip on a victim card for long enough to run a software-based attack (since the ATM eats the card and spits it out when done, it is easy enough for a skimmer device to clone the stripe while the card passes, but outright impossible to establish electrical contact with the chip).
What is interesting to hackers is anything where NFC can be exploited, and as a result - at least to my knowledge - there currently is no tag-based authentication that can't be cloned.
It was wild west, proper ones were never cracked to my knowledge. But it's probably safe to say because of that they are as secure as they are now.
https://en.wikipedia.org/wiki/Conditional_access#Digital_sys...
> there currently is no tag-based authentication that can't be cloned.
Smartcards use ISO 14443, not NFC. Those are related standards I think.
https://en.wikipedia.org/wiki/ISO/IEC_14443
MIFARE tags and cards (which you can clone) are not smartcards (which you can't clone)
Some did, some got close. Most card based systems have to replace the cards every five years or so when their intel suggests groups are getting nearer cracking them.
Ultimately the reason is cost. The conditional access vendors who work on those cards spend a lot lot lot of money on it because that's their entire business and they need to work for a long time or you pay out tens of millions in postage and support. Most chipset vendors shrug their shoulders after two years because it's out of support and they don't care, everyone else gets broken too. In this case Nintendo probably got some significant compensation of Nvidia that hurt them, but it was Nvidia's first real go at it and they fluffed it.
Do they still? Proper smartcards like javacards can be updated by the receiver, it wouldn't affect existing customers if there's a protocol version change or something like that. It's pirates and missed revenue they need to worry about. In any case with internet so widespread those satellite TV networks were on their way out for a long time.
Even my debit card which includes a mandatory EMV smartcard provides for an easy downgrade attack if the chip fails to read three times.
See the Xbox security talk: https://www.youtube.com/watch?v=U7VwtOrwceo
However, the fun part about this particular attack is that it does not require quite the same level of precision. The voltage is dropped incrementally until the CPU starts to make faulty calculations. It just so happens that AES is one of the most complex operations, and thus, the first to start faulting.
https://research.nccgroup.com/2020/10/15/theres-a-hole-in-yo...
That was 8 years ago
Or perhaps the ECC simply works well enough that there's no perceptible data loss for audio?
that said, one of the first copy protection schemes involved writing specific sectors to a magnetic disk with an invalid checksum. when the program would start, it would verify that reading those sectors would return an error, but if you used a regular disk copy program it would not copy the invalid sectors- either resulting in an aborted copy or a copy that would zero out the bad sectors on the target which would not produce the expected read errors on startup telling the program it had been copied.
https://scarybeastsecurity.blogspot.com/2020/06/weak-bits-fl...
http://dmweb.free.fr/?q=node/210
http://dmweb.free.fr/?q=node/1429
https://scarybeastsecurity.blogspot.com/2020/07/turning-400-...
This one describes very similar floppy protection - encoding physical disk parameters in the executable per every individual disk. https://scarybeastsecurity.blogspot.com/2020/12/the-cleveres...
As an aside, I hate all of this. If someone made an open console, I'd buy it in a second. I realise that's probably my computer running linux next to me, but still...
Steam Deck?
The general field is called PUF (physically uncloneable functions)
https://en.m.wikipedia.org/wiki/Physical_unclonable_function
I presume the CPU here was VERY cost conscious and so trade-offs were made.
I have no background in gaming but have worked with flawed "security" solutions. Often the business does not care that the engineers explain how flawed some security thing is before release, if there's more money to be made by not fixing it then it won't get fixed. Often doing all of the right things is MUCH too expensive, either in dollars, size, or power.
It was also more intended as a media chipset and they managed to flog it to Nintendo, and was an early effort by the team involved.
How do you know if external voltage is low if you check it against... a voltage derived from it?
In re "properly secured system": it's a cost-sensitive games console for children, while there's a big incentive against piracy ultimately there's a limit to how much you can defend. And this is the second line of defense, the bootloader having been breached earlier.
> What is body bias?
> Body bias is used to dynamically adjust the threshold voltage (Vt) of a CMOS transistor. While CMOS transistors are usually thought of as having three terminal devices, with terminals for the source, gate, and drain, it’s increasingly common to have a fourth terminal connected to the body (substrate). Because the voltage difference between the source voltage (Vs) and body voltage (Vb) affects the Vt, the body can be thought of as a second gate that helps determine how a transistor turns on and off.
https://semiengineering.com/body-bias-what-it-is-and-why-you...
https://chipwhisperer.readthedocs.io/en/latest/tutorials/cou...
https://chipwhisperer.readthedocs.io
https://www.newae.com/chipwhisperer
https://embedded.fm/episodes/286 (podcast interview)
> sha256(csecret_01)=43449338c1bc8ceb1b3232a611f955f9095254f492117a158528589cd16f2930 NVIDIA TSEC code signing key
Hopefully not.
Skimming switchbrew it looks like there is public key crypto as well. https://switchbrew.org/wiki/NRR
So this key leak doesn't mean homebrew can be signed for unmodified consoles.
EDIT:
Well, some clever guy ;-) reminded them that the T210 chip (the main CPU)
has a proprietary NVIDIA "security processor" called TSEC, which has: [2]
(1) its own SRAM (protected from the rest of the system)
(2) its own "secure boot" (protected from the rest of the system)
(3) bus mastering capabilities
(4) and.. is able to DMA to ARM7's memoryhttps://github.com/CAmadeus/falcon-tools https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3439...