@hackaday@hackaday.social The original article is pretty cool --> https://donjon.ledger.com/blog/rp2350-secure-debug-laser-fault-injection/
Summarized from their TL;DR:
- destructive process; uses lab equipment worth 250kUSD
- photon emission microscopy finds debug-enable registers on RP2350 A4 die
- fire laser pulses at die to restore debug access (which had been permanently disabled in the chip's OTP config) to the chip’s Secure world
- recover secret from OTP memory.
🤯
(Also, the photos...!)
