Email: Password: Remember Me | Create Account (Free)

Back to Subject List

Old thread has been locked -- no new posts accepted in this thread
???
02/16/08 07:55
Read: times


 
#150921 - you apparently don't understand my point, Richard
Responding to: ???'s previous message
...which is, I *am* the offended party. And, in an attempt to avoid jail, I am trying to learn everything possible on ways how to protect myself. To do that, I need to distinguish good ways of protection from those which don't work.

Now, the likely scenario goes like this: Jan Waclawek, as a naive designer/would-be-enterpreneur designs his product. He knows the product can be copied, so he blindly believes what the chipmakers suggest*: use of lock bit(s) prevents chip readout and verbatim copying. He borrows a fortune and sinks it into production of the product. After the initial huge success, the market is soon flooded by a verbatim copy offered roughly at a price of the parts. Murder, inprisonment, wife and kids sold into slavery.

Who was guilty?

In fact, it does not matter what's the answer: Jan Waclawek's life is already ruined. The error he made was the blind faith in the lock bit's power. Or was it his blind faith in truth, love and justice?

Hereby, let's make absolutely clear: there is enough evidence in the public that the lock bit of certain popular '51 derivatives CAN be broken with commonly available $$$ equipment and roughly the same amount cost of labour (the value of which this of course wildly varies geographically). No $$$$$$$ electron microscopes, no $$$$$$$ ion milling machine, not even the nasty chemistry for decapsulation and $$$$ microprobes. In other words, that's roughly the value you can reasonably put behind such a lock. If your property is worth more, you need to get a better door/lock/police combination.

Unfortunately, the manufacturers don't publish reliable and verifiable data on the efforts they put behind the lock bit, not for the commonplace mcus. They do *some* of this in case of smartcards, but that's out of reach (and impractical, too) for standard mcu-based products.

This is the reason why I am interested in trying to break into chips. If I succeed, as a dangling amateur, I know the value of this protection is nil. If I succeed to pay a moderate amount of money to a "service" to recover the code, I know the value of this protection is low.

And, I want more. I don't want to make this research for myself anymore. The chipmakers DO make this - for example for the smartcards. I want them to say clearly: this is a cheap product, don't expect value for the lockbits; and this is a high end product, we put expertise and some extra processing/silicon area into this one, please pay more. I want the same amount of protection they put into smartcards, in a not-only-four-legged product, and am willing to pay a fair price for it.

They don't have such policy, and they won't until something will push them. I will never be in the position to push it through sales volumes, so I try to push it trough public opinion.

Selfish? Yes. Sorry. I need to pay *my* bills. Here and now; I can't wait until the perfect society comes true.

Jan Waclawek


---
* They don't *assert* it, though. Read the datasheets carefully.

List of 71 messages in thread
TopicAuthorDate
Security-breaking threads            01/01/70 00:00      
   Mostly bad            01/01/70 00:00      
      put that in the rulse and ...            01/01/70 00:00      
   Reverse Engineering            01/01/70 00:00      
      Why would this be the case?            01/01/70 00:00      
         legal, maybe, but worthless            01/01/70 00:00      
      Reverse Engineering            01/01/70 00:00      
         locked doors            01/01/70 00:00      
            a couple of points ...            01/01/70 00:00      
               Thief?            01/01/70 00:00      
                  Ironically the Chinese Wall            01/01/70 00:00      
                  IANAL, but...            01/01/70 00:00      
                     Are you sure?            01/01/70 00:00      
                  the law can be interpreted in many ways            01/01/70 00:00      
               by the time you'll decide...            01/01/70 00:00      
                  the short happy life of ... Jan Waclawek?            01/01/70 00:00      
                     you apparently don't understand my point, Richard            01/01/70 00:00      
                        It should be how to Protect Your MCU rather then h            01/01/70 00:00      
                        perhaps I do            01/01/70 00:00      
                           Fair use, security, and all that            01/01/70 00:00      
                              It's simpler than that            01/01/70 00:00      
                                 What harm?            01/01/70 00:00      
                                    If you really want to do that            01/01/70 00:00      
                                       A greater harm            01/01/70 00:00      
                                          Have you gone one assumption too far?            01/01/70 00:00      
                                             Republicans, believe .... AIDS            01/01/70 00:00      
                                                mingling the issue            01/01/70 00:00      
                                                   Which link ?            01/01/70 00:00      
                                                      find it yourself            01/01/70 00:00      
                                                         You find it and Its IAR policy not yours            01/01/70 00:00      
                                                            no, it is not, I'm sure            01/01/70 00:00      
                                                               what an IAR in code ...            01/01/70 00:00      
                                                                  not witrh a Keil eval            01/01/70 00:00      
                                                                     Thats company policy            01/01/70 00:00      
                                                                        I sure can make this decision that            01/01/70 00:00      
                                                                           Is leasing Compiler legal ? . I will never do that            01/01/70 00:00      
                                                                              I don't quite understand this..            01/01/70 00:00      
                                                                                 That's why it requires no treatment here            01/01/70 00:00      
                           Would you?            01/01/70 00:00      
   Slap in the face!            01/01/70 00:00      
      Recovering lost code            01/01/70 00:00      
   Don't help pirates but...            01/01/70 00:00      
   FAQ            01/01/70 00:00      
   it sure is immoral to steal code            01/01/70 00:00      
      The morality of repairs.            01/01/70 00:00      
   I've done it legally and ...            01/01/70 00:00      
      Faulty logic            01/01/70 00:00      
         evidently you missed my exception            01/01/70 00:00      
            False statements            01/01/70 00:00      
               GPL as 'protection' LOL            01/01/70 00:00      
      Security through obscurity            01/01/70 00:00      
         other possibilities            01/01/70 00:00      
            Malund you come to conclusion very early !            01/01/70 00:00      
               Are you sure?            01/01/70 00:00      
                  OK, so let's circumvent this problem...            01/01/70 00:00      
               then why have you done so?            01/01/70 00:00      
                  Did that link open your eyes            01/01/70 00:00      
                     I do not care, my code is worthless in hex            01/01/70 00:00      
         This one is on you, Craig ... the buck stops there            01/01/70 00:00      
            Competence.            01/01/70 00:00      
               I know of many 'unteachable'            01/01/70 00:00      
                  That's what put options are for ...            01/01/70 00:00      
                     Let's not promote fakery in the profession            01/01/70 00:00      
   Answer to the original question            01/01/70 00:00      

Back to Subject List