It’s as of yet unclear how many other manufacturers leave
their firmware updating sequences unsecured. Appotech is
a relatively minor player in the SD controller world;
there’s a handful of companies that you’ve probably never
heard of that produce SD controllers, including Alcor
Micro, Skymedi, Phison, SMI, and of course Sandisk and
Samsung.
Which begs the question: so why target Appotech rather than Sandisk or Samsung?
If you watch the presentation, it's pretty funny why they used the Appotech chipset:
They managed to read out the embedded raw-flash on one device, and when they searched for the vendor/device, the third link that popped up on Baidu brought them directly to a download for the windows based firmware-update-tool (in chinese, of course)... so much for a headstart in analyzing the firmware :-).
Comments
If you watch the presentation, it's pretty funny why they used the Appotech chipset:
They managed to read out the embedded raw-flash on one device, and when they searched for the vendor/device, the third link that popped up on Baidu brought them directly to a download for the windows based firmware-update-tool (in chinese, of course)... so much for a headstart in analyzing the firmware :-).