Тёмный

Looking at the PCB & Chips - Hardware Wallet Research #2 

LiveOverflow
Подписаться 893 тыс.
Просмотров 59 тыс.
50% 1

We start the research by looking at the chips, documentations and manuals.
research: wallet.fail
DISCLAIMER: The security research shown here was done a while ago and since then the software and hardware was updated; These videos are not sponsored or endorsed by Ledger.
ST: www.st.com/en/...
STM32F04 Datasheet: www.st.com/res...
=[ ❤️ Support ]=
→ per Video: / liveoverflow
→ per Month: / @liveoverflow
=[ 🐕 Social ]=
→ Twitter: / liveoverflow
→ Website: liveoverflow.com/
→ Subreddit: / liveoverflow
→ Facebook: / liveoverflow
=[ 📄 P.S. ]=
All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.
#HardwareSecurity

Опубликовано:

 

29 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 145   
@LiveOverflow
@LiveOverflow 5 лет назад
Sorry for those who need captions! I forgot to publish them :S but they should be there now! Please let me know right away when I forget them for a video
@lucemansster
@lucemansster 5 лет назад
Hey, could you take a look at the recent windows patch pertaining to IE and uts renote code execution bug? Im interested to see your views on it. ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-65XOWNwXgvU.html
@hubmartin
@hubmartin 5 лет назад
Hello, I was going to look at your "making of" video but it seems private now. It is for Patreons only now ? Thanks a lot.
@LiveOverflow
@LiveOverflow 5 лет назад
Nono, it turned into a two day stream, so just editing them together and uploading them as one video soon
@koenigsbier50
@koenigsbier50 5 лет назад
Hey hello, I'd like to know how did you open the Chrome Developer Console for the Ledger Manager App? It doesn't exist anymore but I still have it in my Chrome Apps. However it seems to only open the Ledger Manager Desktop Application. So did you manage to use the Developer Console because you ere using an older version of the Ledger Manager Chrome App? Or is there a way to really attach a developer console? Thanks for your answer
@LiveOverflow
@LiveOverflow 5 лет назад
In the chrome extensions menu there should be links to open the dev console and inspect the background page etc. but i havent checked the new app and how it all works now
@GRBtutorials
@GRBtutorials 5 лет назад
Hello, electronics hobbyist here. The markings on the ST chip are most likely some kind of special internal number, either ST's or Ledger's (you can get custom labelling on chips if you order enough of them, and Ledger surely did), in order to conceal the secure chip's identity (even if it's obvious after inspecting the other chips). As for the other chip, a boost converter is a kind of DC-DC converter that boosts (hence the name) DC voltage. Say, you have 3.3 V and want 5 V, then you can use a boost converter. And yes, it's most likely for producing the voltages required to drive the display. The output current cut-off function is a safety feature against overcurrent (which could burn the chip), like in the event of a short circuit.
@jesperahman738
@jesperahman738 5 лет назад
OLED displays usually need a slightly higher supply voltage. Typically 12V for small ones like this.
@5speedfatty
@5speedfatty 5 лет назад
that is one hell of a nice camera man. I'd say I'm jealous, but I wouldnt have a use for anything that extreme, not in the way of a camera anyway. so you enjoy that camera man. if it makes you feel better about your shots then take more of them man. I would assume its hella useful for doccumenting hardware and PCB's.
@kesmik
@kesmik 5 лет назад
holy sh!t i love hw related hacking :) Hope to see more GSM videos tho :)
@JohnDlugosz
@JohnDlugosz 5 лет назад
What kind of camera and lens?
@LiveOverflow
@LiveOverflow 5 лет назад
I have it linked in the description. It’s a Canon 80D and the Canon EF-S 35mm 1:2.8 macro lens
@JohnDlugosz
@JohnDlugosz 5 лет назад
@@LiveOverflow I see. I use the 70D which looks like an older version of the same thing (split-pixel CMOS, articulated screen). I've used Canon EOS bodies since they came out in 1987. Happy to give pointers or answer questions.
@cmatthew91
@cmatthew91 5 лет назад
I solved my first CTF challenge at ctflearn.com, thanks for the quality videos
@marwanghamloush2662
@marwanghamloush2662 5 лет назад
**appreciates beautiful shots**
@protectedmethod9724
@protectedmethod9724 5 лет назад
***Appreciates appreciative comments***
@irfangazi1473
@irfangazi1473 5 лет назад
Holy shit ! Those camera shots look so professional Hard to believe it is made by one person also maintaining a full time pentesting job
@LiveOverflow
@LiveOverflow 5 лет назад
#nolife But thanks :3 glad the work was worth it
@KentoNishi
@KentoNishi 5 лет назад
@@LiveOverflow Love the quality!
@bourne_
@bourne_ 5 лет назад
JTAG? That sounds terrible @Louis Rossmann :D
@k1ngjulien_
@k1ngjulien_ 5 лет назад
JTAG is really nice, Apple just uses terrible connectors :D
@roridev
@roridev 5 лет назад
@@k1ngjulien_ > sees JTAG. >Instaly goes to PP3V3G3H
@bourne_
@bourne_ 5 лет назад
@@roridev why do I know the reference even thou I don't repair Macs myself and I don't look at documentation while watching LR? :D Guess he talks about "PP3V3 Hot" all the time :D
@GeoffBernard
@GeoffBernard 5 лет назад
I really enjoyed those shots from the new camera. I got a good laugh from your commentary while I "just enjoyed the footage from your $1,500 camera" :)
@MadTracki
@MadTracki 5 лет назад
That B-Roll footage is actually quite good and adds a new charme to your video. Stay up with that!
@mook403
@mook403 5 лет назад
JTAG? I have a bad feeling the chip is going to threaten to ban you from Xbox LIVE if you mess this up!
@Kong_plays
@Kong_plays 5 лет назад
Im loving the hardware wallet videos :)
@RoiEXLab
@RoiEXLab 5 лет назад
"It can speak USB" ahh I love when hardware chips are treated as humans ^^
@GRBtutorials
@GRBtutorials 5 лет назад
0:24 But if I hit the subscribe button, I'll unsubscribe from your channel and that number will go down!
@Arthur-qv8np
@Arthur-qv8np 5 лет назад
5 mysterious pins on the board and an enabled JTAG;) ...
@LiveOverflow
@LiveOverflow 5 лет назад
;)
@instantkaffeguld
@instantkaffeguld 5 лет назад
"So appreciate them!" JAWOHL! 🤣
@harshthakur7215
@harshthakur7215 5 лет назад
Hey, you stopped the telco series -_-
@Torterra_ghahhyhiHd
@Torterra_ghahhyhiHd 4 года назад
where have you been at al 2020. ;u..!! just gone from youtube. :(..!!
@gabiold
@gabiold 5 лет назад
Most of the time the labeling is not custom, it just does not fit on the package. This is always the case for small packages, like SOT-23, but that chip might also to small to fit the full length part number. It is worth looking at the datasheet's "Packaging specifications", and maybe "Ordering informations" section to find out the chip markings, which one belongs to which part number. Mostly the complete part numbers are long, because they not just contain the chip name but also the classification (industrial, consumer grade), maybe operating frequency range if there are multiple choices, access time for RAMs, etc...
@persianrogue4614
@persianrogue4614 5 лет назад
nice explaining with electronic parts specially with drawing and zoom the camera .ur d best 8)
@TheChemicalWorkshop
@TheChemicalWorkshop 5 лет назад
I bet you can reprogram that puppy just like arduino or smth Maybe even try serial commands somehow
@lycankarmah1976
@lycankarmah1976 5 лет назад
The ST8R00 is a step up DC to Dc converter, it is used to take a lower voltage and rise it to a higher one. (With a voltage of around 4/6V can provide from 6 to 12V. It might be used to supply some parts of the circuit that works with a higher voltage of the 5V of usb like the oled screen
@LiveOverflow
@LiveOverflow 5 лет назад
cool yeah, that was also my guess
@karlkastor
@karlkastor 5 лет назад
JTAG is an industry standard for verifying designs and testing printed circuit boards after manufacture.
@AndrewCerny
@AndrewCerny 5 лет назад
Best camera work ever! Totally worth the $1500
@gender_nihilism
@gender_nihilism 5 лет назад
you know you're early for a LiveOverflow video when it's not captioned yet
@LiveOverflow
@LiveOverflow 5 лет назад
Oh damn i forgot the captions??? Thanks for letting me know!
@nunofelicio
@nunofelicio 5 лет назад
In what way "Vires in Numeris" is "fancy language" ?....... Man that is Latin.... The way you talked about was like is was leetspeak.. :(
@balazs4112
@balazs4112 5 лет назад
I thought the best thing you can do with JTAG is this: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-a67p6pziKz8.html Will be waiting what you can do with those unnamed test (SWD/JTAG) points.
@adambzh
@adambzh 5 лет назад
didn't get anything useful, JTAG? easily disabled by sceure bit/fuse, any none stupid manufacturer will disable it by default, even it just a toster controller
@mEllzee
@mEllzee 2 года назад
If I reset the nano X, is it possible for anyone including ledger, to be able to extract the previous seed phrase?I need to send mine back for warranty. Is it safe to restore my crypto on the replacement device using my seed phrase? Will the one I return be certain unhackable?
@nullderef
@nullderef 5 лет назад
The boost converter essentialy just bumps up the voltage idk for what though maybe the display.
@andreicadar2224
@andreicadar2224 5 лет назад
Where can i find you and have a quick chat and ask you questions about how did you do that and that? Btw use your camera skills as a second job :))
@ChrisEU14
@ChrisEU14 5 лет назад
Maybe you should use a higher f-number, so the aperture is more closed. That way you'll get more depth of field and more of the small chip is sharp and i focus.
@mythoughts1679
@mythoughts1679 5 лет назад
Lol jtag (hardware debugger) enabled in a ledger device you can directly manipulate registers and CPU values
@willful759
@willful759 5 лет назад
*_fancy language_*
@Rednesswahn
@Rednesswahn 5 лет назад
I don't want to hit the subscribe button! It would unsubscribe me from this channel!
@jjppmm29
@jjppmm29 5 лет назад
appreciate my artistic skills with a camera damn it (ノಠ益ಠ)ノ彡┻━┻
@daydreamingcase
@daydreamingcase 5 лет назад
I just came here to appreciate the slick photos ;) what camera did you buy?
@abc321meins
@abc321meins 5 лет назад
hah! 3:00 The video is so high res, I extracted your finger print out of it! :P
@CryptotagOfficial
@CryptotagOfficial 5 лет назад
Please make sure to keep your backup phrase secure by engraving it in titanium, check it out at cryptotag.io
@birb9254
@birb9254 5 лет назад
I'm learning how to hack right now and I want to ask on where will I start learning how to pwn.
@paulhendrix8599
@paulhendrix8599 5 лет назад
Thanks a lot for the Pay TV smart card tip!
@e1337r0x0r
@e1337r0x0r 5 лет назад
Boost converter is for power management.
@robertm.6243
@robertm.6243 5 лет назад
i like the "i dont care about cookies" addon
@mikelinsi
@mikelinsi 5 лет назад
7:21 I like these short interruptions. But can you explain how you mean this? is it total important or not for you? There a people how not have maybe the same skills in langue like dyslexia and more.
@LiveOverflow
@LiveOverflow 5 лет назад
It’s just a joke of course. Who cares about that ;)
@chenseanxy
@chenseanxy 5 лет назад
Probably stop down to a smaller aperture for the non-beauty shots? It will increase the depth of field greatly and show clearer image
@chenseanxy
@chenseanxy 5 лет назад
Fantastic beauty shots tho..
@zoes17
@zoes17 5 лет назад
Only thing I can figure about the NB0 chip might be this: imgur.com/a/UYSYYhF
@LiveOverflow
@LiveOverflow 5 лет назад
interesting! I wonder if that's coincidence or somebody liked that as a reference :D
@Lfomod1Dubstep
@Lfomod1Dubstep 5 лет назад
Great video! :)
@koenigsbier50
@koenigsbier50 5 лет назад
Awesome! I'm into learning MCU programming recently and hoping one day I could hack some smartbands (aka fitness trackers) I'm not a low-level programmer at all, just a beginner in embedded systems so your videos on reverse engineering a Ledger Nano S are just perfect for me right now. I understand what you're talking about and at the same time learning new things. Thanks a lot
@user-zu1ix3yq2w
@user-zu1ix3yq2w 5 лет назад
Quality's so good, someone could reverse engineer your fingerprint(s). Like they did with chancellor Merkel's.
@gcm4312
@gcm4312 5 лет назад
Out of curiosity... how long did this research take? And do you have some sort of methodology of keeping track of what you find along the way?
@r00tb33
@r00tb33 5 лет назад
waiting for next video...
@melluh
@melluh 5 лет назад
These hardware wallet videos are awesome!
@FlesHBoX
@FlesHBoX 5 лет назад
The ST8R00 is basically a step down converter for power delivery. Essentially a buck converter, used to take the voltage that the USB delivers and lower it to be usable by the components that run on lower voltages on the board.
@AnianBrosig-yv3jn
@AnianBrosig-yv3jn 5 лет назад
the datasheet in the video states 6 to 12 V output, not sure where this is used though
@mrsoundso4897
@mrsoundso4897 5 лет назад
@@AnianBrosig-yv3jn As seen in another comment: "Probably to power the oled screen, which typically requires something around 12V"
@positivemelon7578
@positivemelon7578 5 лет назад
I'm pretty sure it's a step *up* converter
@FlesHBoX
@FlesHBoX 5 лет назад
@@positivemelon7578 Yeah, if it's outputting 6-12v it would have to be, I'm pretty sure USB only delivers 5v ?? But I can't imagine anything on that board needing 6- 12v...
@mustafapc19
@mustafapc19 5 лет назад
Appreciating THEM
@gcm4312
@gcm4312 5 лет назад
hey, nice camera shots
@dextermatherz8608
@dextermatherz8608 5 лет назад
I don't understand most of these videos but I still love to watch them all. Good job keep them coming!!
@_iphoenix_6164
@_iphoenix_6164 5 лет назад
"I have no clue what I'm doing, but it looks good" - LiveOverflow
@dnns1896
@dnns1896 5 лет назад
Great video. I was not able to follow the information as I was too excited about your shots, but that shots were amazing :P
@Novastuffnow
@Novastuffnow 5 лет назад
Shots apericated
@forresthilton9289
@forresthilton9289 5 лет назад
screw the timeline, the videow would be better if you hadn't menchond the Crome extension until you needed to
@stephenkamenar
@stephenkamenar 5 лет назад
i like the crypto themes
@kebien6020
@kebien6020 5 лет назад
I tried pushing the subscribe button but the number went down instead. What did I do wrong?
@mebibyte9347
@mebibyte9347 5 лет назад
Love the photography. Great choice on getting that camera! Great video as always!
@metaorior
@metaorior 5 лет назад
chrome again xDDDDDD
@cyrustakem7993
@cyrustakem7993 5 лет назад
The boostconverter is like the "power supply" for the chips
@noahhounshel104
@noahhounshel104 5 лет назад
APPRECIATE THEM
@mcmundn8544
@mcmundn8544 5 лет назад
I APRECIATE !!1!!!11!
@dasten123
@dasten123 5 лет назад
0:16 "vires in numeris"? I thought that means "lots of viruses"
@abhiramshibu
@abhiramshibu 5 лет назад
JTAG is normally a programming interface
@Veso266
@Veso266 5 лет назад
what do you do for a living beside youtube?
@LiveOverflow
@LiveOverflow 5 лет назад
I haven't really earned anything with youtube. I just created a business for this channel and started last week trying to earn a side-income with RU-vid. My main job is being a security consultant doing pentesting and security code audits.
@tom_the_geek8929
@tom_the_geek8929 5 лет назад
tipo-tipo!
@carloschuler5202
@carloschuler5202 5 лет назад
I think they use the battery chip thing as a constant current driver
@user-rg1jp2us4o
@user-rg1jp2us4o 5 лет назад
appreciated
@jakeyyyyyyyy
@jakeyyyyyyyy 5 лет назад
10:45 :thinking: sound like xbox exploit
@simonengelhardt7653
@simonengelhardt7653 5 лет назад
Love the camera shots. Keep doing it.
@MakeNjoy
@MakeNjoy 5 лет назад
Honestly, the constant focusing of the camera is quite irritating.
@LiveOverflow
@LiveOverflow 5 лет назад
haha sorry. yeah I was playing with it. I guess I was a bit too "artistic" with it :P
@MakeNjoy
@MakeNjoy 5 лет назад
@@LiveOverflow I can appreciate that. I also find it wierdly satisfying when the focus is nailed perfectly.
@achrafpokater6010
@achrafpokater6010 5 лет назад
No come on, Show us more of your finger prints x)
@DantalionNl
@DantalionNl 5 лет назад
The low F stop for your b-roll is fine but I suggest having an higher F stop for your main video so more of the object you record can be infocus at a given time.
@LiveOverflow
@LiveOverflow 5 лет назад
yeah I guess it was a bit too annoying at points. It was my very first experiment using such a camera. Before deciding to buy it I didn't even know about f-stop! xD
@Shinika01
@Shinika01 5 лет назад
JTAG in the next video, yeeey !!!! :D
@soviut
@soviut 5 лет назад
The new camera shots look great.
@sunfrost
@sunfrost 5 лет назад
I love the new camera. Great footage.
@vasiliskonstantinou8577
@vasiliskonstantinou8577 5 лет назад
Finally i was waiting patiently all weak :)
@user-cz9ss4yq4x
@user-cz9ss4yq4x 5 лет назад
7:22
@cprn.
@cprn. 5 лет назад
How is that safe to show us your mnemonic backup phrase?
@LiveOverflow
@LiveOverflow 5 лет назад
maybe... probably... obviously it's not a real backup phrase? ;)
@cprn.
@cprn. 5 лет назад
You cheater! XD
@cprn.
@cprn. 5 лет назад
TBH I thought maybe there's a way to generate a new key on the device and you simply did that after recording a video about how to get the phrase out. Maybe. IDK.
@enaechuong1024
@enaechuong1024 5 лет назад
Nice video, keep it up mate
@dxlultra1020
@dxlultra1020 5 лет назад
We appreciate them! 😃
@j3r3miasmg
@j3r3miasmg 5 лет назад
I miss the face.
@_kett2164
@_kett2164 5 лет назад
what camera/ lens did you get?
@LiveOverflow
@LiveOverflow 5 лет назад
I have it linked in the description. It’s a Canon 80D and the Canon EF-S 35mm 1:2.8 macro lens
@_kett2164
@_kett2164 5 лет назад
@@LiveOverflow I really should have looked in the description before I asked...
@LiveOverflow
@LiveOverflow 5 лет назад
Don’t worry about it :)
@Koto-Sama
@Koto-Sama 5 лет назад
i am confused about the hardware. why is ther a boost converter? ships run on 1.62 V to 5.5 V or 2.0 - 3.6 V
@LiveOverflow
@LiveOverflow 5 лет назад
maybe I also identified the wrong chip... I couldn't find anything about the display, and I thought maybe that the display needs a high voltage? But that is my guess with a lack of electronics knowledge .
@Karthor.
@Karthor. 5 лет назад
Its probably for the Panel supply voltage for the LCD(SSD1306) that requires 7-15V while the IC logic of the LCD just needs 3.3V
@Koto-Sama
@Koto-Sama 5 лет назад
@@LiveOverflow i found the same ship and the inductor above is typical for boost circuits. all the traces seem to go to the Display. i thought it would be a I2C, 3.3v Display. XD
@andersbl02
@andersbl02 5 лет назад
Love you
@damejelyas
@damejelyas 5 лет назад
Helooooooi
@damejelyas
@damejelyas 5 лет назад
Run to like the video. then watch
@LiveOverflow
@LiveOverflow 5 лет назад
plz watch first before rating it :)
@GRBtutorials
@GRBtutorials 5 лет назад
@@LiveOverflow It doesn't matter, you can change your mind afterwards (and I highly doubt I wouldn't like one of your videos).
@vkredgod2340
@vkredgod2340 5 лет назад
EarLY
@grave0x
@grave0x 5 лет назад
Woah
@abhinavpalacharla8175
@abhinavpalacharla8175 5 лет назад
Does anyone know where I can find apache2.4 settings for the apache2.conf configuration file in Linux?
@InvestX
@InvestX 5 лет назад
I love your videos, I also make crypto videos if anyone is interested 😉
@akosmohacsi8136
@akosmohacsi8136 5 лет назад
You are lying
@J-wm4ss
@J-wm4ss 5 лет назад
First
@situationxd8650
@situationxd8650 5 лет назад
Ok
@situationxd8650
@situationxd8650 5 лет назад
I sir....great video please make a video about making own python tools and how they works...
@meithecatte8492
@meithecatte8492 5 лет назад
He has a video about programming in python, go watch it!
@damejelyas
@damejelyas 5 лет назад
This channel is not for programming
@situationxd8650
@situationxd8650 5 лет назад
@@damejelyas what you want to say....
Далее
It’s Been a Good Run, Phone Providers.
26:31
Просмотров 4,7 млн
Ко мне подкатил бармен
00:58
Просмотров 119 тыс.
I used to hate QR codes. But they're actually genius
35:13
6 Must-Have Security Gadgets That Fit in Your Pocket
9:03
SKIN EFFECT! Why Current Doesn’t Run Inside
13:12
Просмотров 249 тыс.
Threat Models - Hardware Wallet Research #1
14:00
Просмотров 68 тыс.
Designing Billions of Circuits with Code
12:11
Просмотров 597 тыс.
ESP32 Guide 2024 | Choosing and Using an ESP32 Board
41:06
Ко мне подкатил бармен
00:58
Просмотров 119 тыс.