@lupyuen I wish the standard reply to that were not to "disable SWD" (or not have debug ports), but to configure chips to lock debugging until an erase-all command was issued, and to make tampering evident.

@lupyuen Sure it's a bit more work, because it has to be made sure that when the device is erased there is no key material left on, say, still accessible external flashes. But given that vendor driven firmware updates usually end long before the hardware becomes unserviceable, that's what makes the difference between years of post-market usage and landfill.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.