Post

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

Ledger Donjon used photon-emission microscopy to localize the RP2350’s DEBUGEN logic, then laser pulses to set the two bits needed to restore Secure debug despite permanent debug-disable settings. A rescue reset kept firmware from reapplying a runtime OTP lock, allowing the researchers to recover a challenge secret. The attack requires destructive backside decapsulation, specialized equipment, and physical access, but exposes a real gap between OTP policy, mutable override registers, and reset-time behavior.

HN commenters debated the cost and practicality of the lab setup, and whether the result is a lesson about trusted-hardware threat models rather than a conventional software vulnerability.