news.volyx.in

Can you get root with only a cigarette lighter? (da.vidbuchanan.co.uk)

681 points by 1317 · 669 days ago · 150 comments on HN

Article summary

The article discusses a method of exploiting hardware faults using a low-budget tool, specifically a piezo-electric lighter, to induce electromagnetic interference and flip bits in memory. This technique, known as fault injection, can be used to gain root access to a system. The author demonstrates the method by exploiting a laptop's memory bus and gaining access to the system. The technique relies on the ability to induce bit-flips in specific memory locations, which can be used to bypass security mechanisms.

Main themes

  • Hardware Exploitation
  • Fault Injection
  • Electromagnetic Interference
  • Memory Corruption
  • Security Vulnerabilities
  • Low-Budget Hacking

What commenters say

  • Physical access to a device can be used to compromise its security, regardless of software protections.
  • The technique demonstrated in the article is not practical for real-world attacks due to the need for precise control over the electromagnetic interference.
  • The use of fault injection and electromagnetic interference can be used to bypass traditional security mechanisms, such as encryption and access controls.
  • The article's method is not a reliable way to gain root access, as it relies on inducing random bit-flips and hoping for the best.
  • The technique could be used to compromise devices that use trusted execution environments or secure enclaves.
  • The use of a piezo-electric lighter as a tool for fault injection is an innovative and low-cost approach to exploiting hardware vulnerabilities.
  • The article highlights the importance of physical security in protecting devices from tampering and exploitation.
  • The technique demonstrated in the article has implications for the security of devices that use memory corruption and bit-flipping as a means of exploitation.