Skip to content

Comment on Can you reverse engineer an ASIC?parent

Comments

He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs

This is absolutely not how reverse engineering a digital logic ASIC works.

Either the story got embellished through retellings, or this person was a fantasist.

There are people who hack on GPUs but it’s done at the software level.

I did get a kick out of imagining a scene where someone is trying to connect an oscilloscope to a circuit board to reverse engineer the CPU opcodes. That’s like the CSI: Miami version of what this would look like.

Many laymen confuse logic analyzers with oscilloscopes. Don't take it personally - the person you responded to is clearly not a native English speaker.

You absolutely can reverse chips with logic analysis. It is big business in some parts of the world.

You absolutely can reverse chips with logic analysis.

You are not going to reverse engineer a GPU with a logic analyzer and by applying currents to pins.

You could replace oscilloscope with logic analyzer in the comment above and nothing changes. It’s a fantasy story. The GPU I/O is high speed PCIe and memory buses.

If you want to explore the chip you connect it to a PCIe host and use the host. Connecting logic analyzers and applying current to pins does not make sense on any level.

Also, if you think probing high speed signals like PCIe or memory buses with logic analyzers is easy, you’ve probably never tried it. The equipment needed to do that properly is incredibly expensive because even probing those buses slightly incorrectly or with cheap probes will make them fail to work at the speeds they use.

I use this type of equipment every day. I'm aware of the expense - nobody said it was cheap to do this kind of work.

You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no.

Connecting logic analyzers and applying current to pins does not make sense on any level.

Tell me you've never fuzzed a chip without telling me you never fuzzed a chip.

Nobody said it would be easy or cheap, or that fuzzing is the only way to do it. The OP may not have had all the details correct.

But, you certainly can reverse engineer high-density digital electronics this way.

You might be thinking that the hobby-level logic analyzers you're used to, are what folks who are serious about doing this kind of work would be using. Just, no.

No I'm not. I'm referring to the logic analyzers and probes, and fixturing that would be necessary to probe something like this.

It's not as simple as saying "wouldn't be cheap". I'm saying it's virtually impossible for a university student to do for fun with the resources available to them.

Tell me you've never fuzzed a chip without telling me you never fuzzed a chip.

Please don't be snarky. Also please don't take my quotes out of context to try to attack a strawman.

I'm talking about the comment thread we're responding to about someone reverse engineering the opcodes by applying current to the pins.

Nobody is going to be fixturing up an nVidia GPU chip, acquiring enough probes and logic analyzer inputs to measure it, then applying currents to pins, just to reverse engineer the opcodes. You're off trying to argue something else to show off your knowledge on the internet, but you've missed the point of the thread.

If someone wants to reverse engineer a GPU, the first thing you do is plug it into a system and access it through software. Nobody is going to connect logic analyzers to a million pins and re-invent PCIe signaling just because it's technically possible to do.

Your extreme claims that "nobody is going to do that", while I have actually seen people doing exactly that in modern universities and other reverse engineering institutions, just renders your stubborn know-best boring.

Yes, people do this. Yes, it is a lot of tedious work. PCIe signaling is not a panacea - there are reasons to fuzz like this.

I've also seen folks break out a tunneling electron microscope to dig deeper on de-laminated cores.

I'm saying it's virtually impossible for a university student to do for fun with the resources available to them.

Now who's inventing straw man claims? "For fun"? Yes, for fun. "For profit"? Yes, for profit too. At universities? Yes, at universities.

Just give it up. The world is big.

One other bit in support is that the person you’re replying to read “university student” but OP said “Post-Doc” which I guess technically is a student at a university but a post-doc EE is an exceptionally skilled and specialized role who’s likely been working on that specific problem for 8+ years.

I mean, there are universities with hardware reverse engineering labs in operation since the very, very beginning of hardware.

I’m only persisting with the argument because the myopia is revealing.

Err how would one even connect an oscilloscope to these chips, since there are only a few pins but and is digital information in very high speed?

with very, very expensive logic analyzers... But yeah, nothing weird here. Plus OP was retelling a story of someone else doing it, while probably not being a specialist in this field. So I wouldn't take the "random inputs" part literally.

with very, very expensive logic analyzers... But yeah, nothing weird here.

You can’t simply get an expensive logic analyzer and probe PCIe or memory buses at these speeds. There are expensive custom fixtures that need to be made to even begin to be able to probe at these speeds without disturbing the circuit so much that it fails to work. This isn’t like probing the I2C bus on a raspberry pi. It would be like connecting to the pins under the chip. It’s fantasy.

It’s also illogical. If you have a PCIe device, you plug it in to a PCIe host and use the host to interact with it. You don’t start probing pins and trying to apply signals to it.

Your pessimism belies a distinct lack of experience, if not also a dearth of imagination.

Harnesses for such things are not cheap, nor are they something you can just order from Reichelt. But, I assure you, there are reverse engineering labs in the world that can do this. There are technicians who think nothing whatsoever of de-soldering a BGA and using microscopes to rig things up. They do it before lunch, even.

The OP may have some details wrong - they're clearly laymen describing an anecdote - but that doesn't mean for an instance that this "isn't possible".

There is always a higher-speed logic analyzer, capable of operating faster than the consumer device under test. That's how the consumer DUT's get tested at the ATE, in the first place ..

Your pessimism belies a distinct lack of experience, if not also a dearth of imagination.

You keep missing the point and trying to insult my experience in the process.

We're talking about a university student and CPU opcodes. The whole side story about probing the chip is completely irrelevant. This is a software task.

But, I assure you, there are reverse engineering labs in the world that can do this.

We're talking about a university student.

There are technicians who think nothing whatsoever of de-soldering a BGA and using microscopes to rig things up. They do it before lunch, even.

I'm talking about the fixturing required to actually probe those pins. Replacing the BGA is the easy part. You can't probe a large BGA by having a tech remove and replace it. The contrast between you trying to insult my experience while not understanding the task at hand is truly something.

You've chosen a weird hill to die on, given how much you're arguing things that have no relevance to the story.

Maybe your university students aren't as well-funded as my university students, ever thought of that, huh? Maybe your universities are lagging behind the state of the art in the rest of the civilized world. Maybe, you just don't know enough about this subject, actually.

I'm talking about the fixturing required to actually probe those pins.

This just isn't as impossible as you claim. And, there are plenty of reasons to do it.

Just because you can't imagine it, doesn't mean someone else hasn't already actually done it.

Upvoting this purely because I want to see you two argue more hahahhaha

Thank you for taking your time to squash another potential "urban legend" in the making. We've got enough of them already in tech.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.