I don't know whether this is true, but it's definitely possible (there are pin-compatible 64 KiB variants of the MCU). If you use the device without verifying the hardware, it's game over. To prevent Evil Maid attacks, that means checking at EVERY use.https://www.reddit.com/r/ledgerwallet/comments/86b7dk/important_to_everyone_who_bought_a_nano_ledger_s/ …
-
-
I think the chip is currently clocked low anyway and I would definitely try clocking it (the existing chip) high to defeat their new timing checks if you were trying to attack 1.4.1.
-
As I mentioned in the write-up, timing checks likely can't win because both the SE and the UART are slower than the MCU.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.