Ret2libsanity

u/Ret2libsanity@infosec.pub
6 posts · 42 comments

Recent posts

Recent comments

It very well could be.

My guess is they are bypassing some integrity check on signed code by glitching logic in the ASP bootrom. If it’s true then it is very possible there are no fuse banks prepped to patch the bootrom. Which I have seen used to make bootroms patchable.

It’s very hard to protect against glitch attacks. And typically that sort of measure needs to be engineered into the design itself.