Yahoo Groups archive

Lpc2000

Index last updated: 2026-04-28 23:31 UTC

Message

Re: [lpc2000] Re: Flash Security Clarification --- some sad facts

2005-12-26 by Dominic Rath

On Monday 26 December 2005 02:37, rtstofer wrote:
> I guess I am just bored of the month long harangue of Philips.  This
> isn't a discussion, it is a prolonged attack without one shred of
> proof that Philips is either incorrect or hiding something.
Sorry, but please ignore the remainder of this thread. Seems there are more 
people interested in this discussion than those that want to see it stopped.

> I just read through the section in the LPC2292 datasheet (3d paragraph
> of section 6.2) - it seems pretty clear to me.
>
> JTAG doesn't talk to the hardware for programming, it uses IAP which
> is implemented in the boot code.  This from Errata IPA1, 14 NOV 2005.
> One can suppose that the boot code knows what to do about JTAG access
> to flash given that the boot code does that actual programming as well
> as implementing CRP.  If Philips says JTAG is disabled if CRP is
> enabled, where is the proof that they are wrong?
If you're able to access JTAG on the device, you're done. This isn't Philips' 
fault, nor is there anything (reasonable) they could do against it. I doubt 
ARM lets them modify the ARM7TDMI-S macrocell to that extent. JTAG allows you 
to control the core, and is only bound by the limits that apply to any code 
that runs on the device. The manual is unclear regarding when JTAG is enabled 
and disabled - that's why I've tested it myself. I believe the LPCs are safe 
in that regard.

> Go to the source, get the answers in writing, share the results, if
> they aren't covered by an NDA.  Again, there are formal channels for
> this.
If any information regarding CPR was available only under an NDA that would 
make me even more suspicious. Guess we're from two different worlds.

>
> Richard

Regards,

Dominic

Attachments

Move to quarantaine

This moves the raw source file on disk only. The archive index is not changed automatically, so you still need to run a manual refresh afterward.