Reverse Engineering a Furby
poppopret.org
poppopret.org
The Visual6502[1] folks are probably the best example of how well it can be done (assuming you can't afford to pay ChipWorks or FlyLogic to do it for you), but if you're working with a standardish MCU core and some masked ROM, a lower tech solution like the Dangerous Prototypes "rompar"[2] might work.
Probably requires quite a few dies, or plenty of experience in extracting them before you succeed though.
For actually reverse engineering the flash contents, I think it'd be easier to sniff the bus traffic as you probe it, or make a read/write capable emulator that logs what's going on. With the hacked phone-side control library, you could probably build a mostly automated harness to exercise the various settings and see what gets stored in flash.
[2] http://adamsblog.aperturelabs.com/2013/01/fun-with-masked-ro...
"Many Tamagotchis Were Harmed in the Making of This Presentation"
PDF: http://recon.cx/2013/slides/Recon2013-Natalie%20Silvanovich-...
Video (original? talk): https://www.youtube.com/watch?v=WOJfUcCOhJ0
Video (newer talk at ReCon): http://recon.cx/2013/video/Recon2013-Natalie%20Silvanovich-%...
Natalie Silvanovich did this kind of reversing on a few Tamagotchi products with great success.
If only all technical reviews started this honestly...
Maybe these could be used for finding out the contents of the mem chip and the CPU used.
They are fun to play with from a hardware poking perspective.
http://arstechnica.com/security/2013/10/meet-badbios-the-mys...
This article says that the Furby communicates in the same way. It would be interesting if the Furby was a vector for spreading messages via this virus. Very, very interesting.
http://blogs.smithsonianmag.com/smartnews/2013/12/earths-qui...
US Military guidelines do require acoustic isolation of all SCIFs (Secure Compartmentalized Information Facilities). You just need isolation, though; deadening the rooms is not really necessary.
Plus doing it with light is just way cooler.
https://github.com/iafan/Hacksby found via hnsearch.com but I don't think that's where I saw the details last time.
There's this http://news.ycombinator.com/item?id=4984100 too - about open-source furby-like projects.
http://dangerousprototypes.com/docs/Bus_Pirate
I used one of these to reflash the BIOS on a logic board after the utility provided died, without removing the BIOS from the board.