Slashdot Mirror


Unspoofable Device Identity Using Flash Memory

wiredmikey writes with a story from Security Week that describes a security silver lining to the inevitable errors that arise in NAND flash chips. By seeking out (or intentionally causing) defects in a given part of the chip, a unique profile can be created for any device using NAND flash which the author says may be obscured, but not reproduced: "[W]e recognize devices (or rather: their flash memory) by their defects. Very much like humans recognize faces: by their defects (or deviations from the 'norm') a bigger nose, a bit too bushy eyebrows, bigger cheeks. The nice twist is that if an attacker manages to read your device identity, he cannot inscribe it into his own device. Yes, he can create errors — like we did. But he cannot control where in the block they occur as this relies solely on microscopic manufacturing defects in the silicon."

7 of 145 comments (clear)

  1. Famous last words? by migla · · Score: 4, Funny

    "I'm unspoofable! Not even Zeus himself could spoof me!"

    --
    Some of my favourite people are from th US; Vonnegut, Chomsky, Bill Hicks.
  2. Re:Argument from ignorance by Anonymous Coward · · Score: 3, Funny

    The paternity test and court-ordered child support, however, is compelling evidence.

  3. Re:What if one more bit goes bad during normal usa by jojoba_oil · · Score: 4, Funny

    What if one more bit goes bad during normal usage..Identity is gone. Any thing tied to it will stop working.."Very much like humans recognize faces: by their defects"..if your son had plastic surgery without your knowledge..you will fail to recognize him?

    Especially if that plastic surgery was done unintentionally just by looking at him one time too many.

  4. Seems like.. by airfoobar · · Score: 2, Funny

    Microsoft's Windows activation thing could become even more annoying in the future.

  5. lol by Charliemopps · · Score: 2, Funny

    Unspoofable? Buahahahaha!

  6. Re:Defeated by Trusted Computing by Mitchell314 · · Score: 2, Funny

    Yes it can.

    input "Is this VM running slow? (y/n) ", runningSlow$

    --
    I read TFA and all I got was this lousy cookie
  7. Re:Unspoofable? by Nadaka · · Score: 2, Funny

    They have been doing that on the PS3 for years.