Skip to content

Comment on On Hacking MicroSD Cards

Comments

  It’s as of yet unclear how many other manufacturers leave
  their firmware updating sequences unsecured. Appotech is 
  a relatively minor player in the SD controller world;
  there’s a handful of companies that you’ve probably never
  heard of that produce SD controllers, including Alcor 
  Micro, Skymedi, Phison, SMI, and of course Sandisk and 
  Samsung.
Which begs the question: so why target Appotech rather than Sandisk or Samsung?

If you watch the presentation, it's pretty funny why they used the Appotech chipset:

They managed to read out the embedded raw-flash on one device, and when they searched for the vendor/device, the third link that popped up on Baidu brought them directly to a download for the windows based firmware-update-tool (in chinese, of course)... so much for a headstart in analyzing the firmware :-).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.