Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure but conceptually no one should've been able to crack any hashing scheme anyone half-way decent at their job could come up. SHA256 is the default and it's unbroken. Even SHA1 has scant few known collisions. So like...what the heck were they hashing and how that anyone was able to crack it?
 help



Maybe its more like the hash was a well known secure hash but someone managed to extract the salt/private key/signing certificate from the camera?

Most likely is either extracting the private key from the camera or getting the camera to sign arbitrary data. If the signing isn't part of the sensor die itself there's a bus where the image data gets transferred from sensor to signer, so an attacker can inject arbitrary data onto that bus to get it signed, even though they never actually extract the signing key.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: