Elektrine lite

← Feed

@kevinthomas@defcon.social

Post #3673804

2026-07-08 14:19 UTC

@0x00string@infosec.exchange I did not get butt mad I answered the question asked. I appreciate you looking at the algorithm. Yes I was wrong about $5 I was referring to aftermarket but yes that was wrong of me. Anyway I hope the tool helps people on their own personal projects. Your point is fair.

Replies (1)

  • @0x00string@infosec.exchange 2026-07-08 14:23

    @kevinthomas@defcon.social i was wondering if you were going to make me quote you, dude if you didnt mean for this to read extremely buttmad at being asked to provide proof then you need to think about how youre coming across 🤷‍♂️ I was rejected by the International Association for Cryptologic Research. They said submissions should ‘be clear, readable, and self-contained’, ‘look somewhat new and interesting’, and ‘contain proofs or convincing arguments for any claims’. I was none of these. The academic establishment is still blindly trusting hardware-backed secure boot, treating it like an infallible standard wrapped in formal proofs. But those proofs are useless in the real world because secure boot relies on logic branches—and logic locks can be glitched. We have proven that physical fault injection shatters these systems. A $5 voltage glitcher can drop the core voltage for a fraction of a microsecond, force the silicon to skip the signature verification instruction, and bypass the entire security model. The hardware just forgets to check the lock, and the execution door swings wide open. I tried to explain that the 'proof' against this isn't some elegant equation—it's the fact that the execution is the decryption. If an attacker tries to fault-inject the Speck cipher, it doesn't skip a vulnerable logic gate; it spits out garbage plaintext, fetches invalid opcodes, and hard-faults the processor. The entire point is that the machine code is inherently unreadable without the correct cryptographic state. There is no master key. The payload is the ciphertext. But apparently, actually building a bare-metal framework that turns physical exploits into a mathematically unsolvable problem isn't 'academic' enough unless it's wrapped in 15 pages of theoretical fluff. id like for it to help people too. again i think its cool and a fun project. you gotta stop making extremely bold claims about it like that it is "unhackable" when it is for instance more vulnerable to offline recovery than decade old nxp hab secure boot. you also gotta stop acting offended when people ask you to provide proof when youre publishing anything related to crypto, especially while making huge claims like that it is "impenetrable"

    Open ##3673800