Feeds

Boffins deduce chip's crypto just by looking at it

Smartcard hacking enters script-kiddie phase

Choosing a cloud hosting partner with confidence

Black Hat Hackers have released tools that unlock the software stored on heavily fortified chips so researchers can independently assess their security and spot weaknesses.

At the heart of the the release, which was announced Wednesday at the Black Hat Security conference in Las Vegas, is Degate, software developed by Martin Schobert for hardware experts to analyze small silicon structures. It has recently been refined so it can be used by amateurs to analyze chips the size of smartcards.

The tools are the work of cryptographer Karsten Nohl and hardware hacker Christopher Tarnovsky, who are both veteran reverse engineers of extremely sophisticated smart chips.

In 2008, Nohl and a team of colleagues cracked the encryption of the widely used Mifare Classic smartcard after physically dissecting its circuitry and analyzing it with a microscope and optical recognition software. The 18-month task uncovered a proprietary algorithm on one of the chips generated cryptographically weak outputs that allowed attackers to break or clone an individual card in just minutes.

And last year, Tarnovsky cracked the Infineon SLE 66PE one of the most locked-down chips ever put into a consumer device, through a grueling six-month process that involved an electron microscope, microscopic needles, and a steady supply of microcontrollers bought on the surplus market in Hong Kong.

“We found a way now to give everybody the ability to extract software out of smartcards,” Nohl, who is chief scientist at Berlin-based Security Research Labs, told The Register. Degate “can be used by less skilled people, but the results are even more expressive than they were before.”

He estimated that had Degate existed in its current form then, it would have taken a few weeks to reverse engineer the Mifare card.

He compared Degate to disassembler software used by researchers to analyze hundreds of thousands of lines of binary code to figure out how it works.

“Degate is essentially a disassembler in the hardware world,” Nohl said.

The software recognizes structures on chips, traces the connections between them, and pieces together the algorithms implemented by the circuits.

Nohl said the tools are intended to make it easier for software experts to assess the security of chips stored on credit cards and other types of smartcards.

“These smartcards are being abused today for storing proprietary protocols and keeping them away from independent analysis,” he said. “We want to help the software hackers to find more interesting software for analysis.” ®

Beginner's guide to SSL certificates

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.