Episode
071 - Snerd Niped
- Published
- Sep 7, 2024
- Duration seconds
- 5463
- Processing state
processed- Canonical source
- https://unnamedre.com/episode/71
Actions
POST https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Security researcher Thomas Roth (StackSmashing) breaks down his recent hardware reverse engineering exploits on Apple's latest silicon. The discussion covers JTAG access on iPhone 15, USB-C controller vulnerabilities, and low-cost fault injection techniques.
Topics
- Hardware Hacking
- Reverse Engineering
- iPhone 15
- Apple Silicon
- Fault Injection
- USB-C Controller
- BitLocker
- Embedded Security
- JTAG
Highlights
- Main idea: Apple's transition to USB-C on iPhone 15 introduced new attack surfaces via the ACE3 controller
- Practical takeaway: Low-cost tools like the PicoEMP can be used for effective voltage fault injection without expensive oscilloscopes
- Failure mode: Relying on default BitLocker configurations without PINs leaves systems vulnerable to cold boot attacks
- Main idea: Reverse engineering the USB-PD communication protocol reveals undocumented behaviors in M-series Macs
- Practical takeaway: HexTree.io provides micro-courses to democratize specialized hardware security training
Chapters
8:00Analyzing Apple's USB-C Power Delivery: An investigation into the ACE3 controller and how its USB stack differs from documented specifications on iPhone 15 and M-series Macs.28:00Hardware Fault Injection Techniques: The risks of electromagnetic fault injection (EMFI) and using low-cost tools for side-channel analysis.42:00Bypassing Windows Disk Encryption: Discussing the feasibility of cold boot attacks to extract BitLocker keys from memory.49:00Embedded Systems Village at DEF CON: Showcasing accessible hardware hacking boards designed to teach JTAG and glitching to the community.56:00Democratizing Security Research Tools: How the cost of security research is dropping as specialized hardware becomes more accessible and affordable.1:09:00The Culture of Black Hat and DEF CON: A comparison of the professionalized atmosphere of Black Hat versus the community-driven chaos of DEF CON.