20 MSP430 Paparazzi Attack
Early MSP430 families, such as the MSP430F1xx, F2xx, and F4xx, are vulnerable to a semi-invasive attack, first publicly documented in Thomas (2014), in which a camera flash is used to fake out the fuse check while a JTAG debugger attempts to attach in a tight loop.
These chips have two access controls. JTAG is protected by a metal migration fuse; this is a thin trace of metal on the die that permanently breaks when too much current flows through it. Entirely unrelated to the fuse is a 32-byte password that is required to access the serial bootstrap loader (BSL). This password is the interrupt vector table (IVT) at the end of memory, and without it, the BSL allows little more than erasing all of memory. Because the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access