I just forget who did it, which is unfortunate.
I just forget who did it, which is unfortunate.
I found a similar idea here: http://members.iinet.net.au/~lantra9jp1/gurudumps1/decap/ind... The photo in the upper-right looks like it could reasonably be turned into binary, if you knew what you were looking at.
Anyone have any more info about how this actually works?
Start here:
Somewhere in that site they detail the step by step process of decapping, delayering photographing and identifying the logic.
There's also a JavaScript simulator, check it out.
The CCC also had a few lectures about decapping. The most interesting one is about backside scanning the die to bypass the safety features.
https://www.youtube.com/watch?v=dtviiOJ-2hI
It contains lots of info and technical details.
Another one:
https://www.youtube.com/watch?v=KVmpBPbGPsQ
This is what an actual ROM looks like:
https://docs.google.com/document/d/18IGx18NQY_Q1PJVZ-bHywao9...
As the last image shows, the ROM table values are extracted by graphics processing the photo.
It's also possible to dump the ROM by reading it byte by byte, but this depends on the architecture (not always possible) and is typically done for mask ROMs that contain data.