This isn't Hollywood. What actually matters to companies is that some 15-year-old with a Flipper Zero can't trivially break your printer ink DRM scheme, and that your debit card can't be cloned without leaving plenty of evidence.
Worried about nation-state attacks? Then don't rely solely on sub-$1 hobbyist-level chips for your security!
Why wouldn't a person build that into the heart of something important?
Because it's inexpensive and not designed to be tamper-resistant. If preventing this type of thing is your goal there are chips out there designed to break irrepairably if tampered with.
The goal of the bounty is to demonstrate that they aren't just a company making toys for hobbyists, and that they can be relied upon by the industry for basic IoT-level products. They are saying "it won't be completely trivial to extract your proprietary firmware", not "use this chip for your next HSM".
Is there anything about these techniques that are raspberry pi specific? It seems like they're using lasers to identify and flip particular bits in registers.
Some very high end HSMs must be actively powered at all times which makes disturbances in their local environments detectable at all times as well. Getting lucky and drilling through a part of the enclosure that isn't directly protected won't help you if a barometric pressure sensor is tripped as a consequence of breaking the hermetic seal.
That's interesting. I suppose if that technology is in use, the attack would have to occur in a pressure-controlled chamber, so breaking the seal wouldn't cause a change in pressure.
Even a very sensitive pressure checker in a temp controlled sealed box would do it.
Any path can be made into an optical path with a bright enough light. >smile<
[0] https://simkl.com/tv/33956/chaos-communication-congress/seas...
[1] https://media.ccc.de/v/33c3-8127-how_do_i_crack_satellite_an...