Raspberry Pi Hands Out Prizes To All In The RP2350 Hacking Challenge

Raspberry Pi has given out prizes for extracting a secret value from the one-time-programmable (OTP) memory of the Raspberry Pi RP2350 microcontroller – awarding a pile of cash to all four entrants.

The RP2350 went on sale to the public on August 8, 2024, a substantial improvement over its predecessor, the RP2040. One notable area of change was around security; a weakness of the RP2040 had been a factor for some potential customers who regarded it as a non-starter.

Keen to change that perception, Raspberry Pi offered a $10,000 prize to the first person to retrieve a secret value from the OTP memory on the device. According to Pi supremo Eben Upton, "Our aim was to smoke out weaknesses early, so that we could fix them before RP2350 became widely deployed in secure applications."

Hackers were given just one month to make their submissions. Nobody claimed the prize. In September, the prize was doubled to $20,000, and the deadline was extended to the end of 2024. This time, the company received four valid submissions.

All of the hacks required some form of physical access to the chip to retrieve the data. Some tinkered with the power to induce faults, and another ground away part of the chip package and fired a laser at the internals to cause a glitch that could be taken advantage of. A fourth used techniques, including a focused ion beam, to extract the data.

Raspberry Pi also commissioned cybersecurity outfit Hextree to evaluate the chip's secure boot process. By using electromagnetic fault injection (EMFI) – delivering a high-voltage pulse to a small coil on top of the chip – the team was able to inject faults that weren't spotted by the glitch detectors.

While having your hardware hacked is less than ideal (although Upton told us at the time that he realized the company was "painting a target on our backs"), the computer maker was very impressed by the attacks and opted to award $20,000 to each of the winners rather than pick the "best."

We imagine the award money was a bargain compared to the reputational damage that an attack in the field could cause.

Upton described the approach taken by Raspberry Pi as "security through transparency," which contrasts with the "security through obscurity" philosophy in some other part of in the industry, he said.

There is a saying that security by obscurity is no security at all, but the approach taken by Raspberry Pi of publishing the hackers' exploits before mitigations have been implemented might raise an eyebrow or two. At least two will require changes to the hardware. However, as we've noted, all of the exploits require physical access to the microcontroller.

Another challenge is due to start in a few weeks. In the meantime, Upton acknowledged the pros and cons of the transparent approach and said, "The optimum strategy may vary over time, as the installed base of devices with critical exploits increases.

"What doesn't work is a strategy where exploits exist, and are widely known to bad actors, but you put on a brave face and pretend to your customers that everything is fine." ®

RECENT NEWS

From Chip War To Cloud War: The Next Frontier In Global Tech Competition

The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more

The High Stakes Of Tech Regulation: Security Risks And Market Dynamics

The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more

The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics

Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more

The Data Crunch In AI: Strategies For Sustainability

Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more

Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser

After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more

LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue

In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more