Wii Fail: a strong architecture fails on details
Summary
bushing and marcan take apart the security architecture of the Nintendo Wii and show how several implementation errors rendered an impressive chain of trust useless. Several layers of protection do not help if they share the same unchecked assumption. Mass-market hardware turns rare implementation errors into permanently available research objects.
Ideas
- The Wii spreads security functions across several processors and software layers.
- Subtle errors made it possible to move from limited access to running custom software.
- Unchangeable hardware errors make a complete repair after the fact difficult.
Recommendations
- Reconstruct chains of trust from the first immutable code up to the application.
- When developing devices, also consider recovery after keys have been compromised.
References
Links to the original source and the Web Archive open in a new tab.