Comment by MertsA

4 years ago

I'd imagine you wouldn't necessarily need to decap the entire chip, just the small part of the die with the fuses. The Xbox 360 Kamikaze hack involved drilling into the package to hit one of the bond wires so coming up with a way to use a laser engraver or just a UV light source sounds plausible. As for erasing all fuse bits bricking the chip, aside from the headache of reverse engineering it surely those fuse bits are all wiped clean when the chip is manufactured. Wouldn't there be some method over a JTAG interface to set the relevant bits if you knew which ones were for some key and which were there for platform configuration values? It might not work in circuit but I'd kind of expect that to be programmed after packaging so surely it's brought out on some pin.

> aside from the headache of reverse engineering it surely those fuse bits are all wiped clean when the chip is manufactured. Wouldn't there be some method over a JTAG interface to set the relevant bits [...]

Good point.