Episode

071 - Snerd Niped

Podcast
Unnamed Reverse Engineering Podcast
Published
Sep 7, 2024
Duration seconds
5463
Processing state
processed
Canonical source
https://unnamedre.com/episode/71
Audio
https://traffic.libsyn.com/secure/reverseengineering/071_-_Snerd_Niped.mp3?dest-id=552832
JSON
/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped
Markdown
/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Security researcher Thomas Roth (StackSmashing) breaks down his recent hardware reverse engineering exploits on Apple's latest silicon. The discussion covers JTAG access on iPhone 15, USB-C controller vulnerabilities, and low-cost fault injection techniques.

Topics

  • Hardware Hacking
  • Reverse Engineering
  • iPhone 15
  • Apple Silicon
  • Fault Injection
  • USB-C Controller
  • BitLocker
  • Embedded Security
  • JTAG

Highlights

  • Main idea: Apple's transition to USB-C on iPhone 15 introduced new attack surfaces via the ACE3 controller
  • Practical takeaway: Low-cost tools like the PicoEMP can be used for effective voltage fault injection without expensive oscilloscopes
  • Failure mode: Relying on default BitLocker configurations without PINs leaves systems vulnerable to cold boot attacks
  • Main idea: Reverse engineering the USB-PD communication protocol reveals undocumented behaviors in M-series Macs
  • Practical takeaway: HexTree.io provides micro-courses to democratize specialized hardware security training

Chapters

  1. 8:00 Analyzing Apple's USB-C Power Delivery: An investigation into the ACE3 controller and how its USB stack differs from documented specifications on iPhone 15 and M-series Macs.
  2. 28:00 Hardware Fault Injection Techniques: The risks of electromagnetic fault injection (EMFI) and using low-cost tools for side-channel analysis.
  3. 42:00 Bypassing Windows Disk Encryption: Discussing the feasibility of cold boot attacks to extract BitLocker keys from memory.
  4. 49:00 Embedded Systems Village at DEF CON: Showcasing accessible hardware hacking boards designed to teach JTAG and glitching to the community.
  5. 56:00 Democratizing Security Research Tools: How the cost of security research is dropping as specialized hardware becomes more accessible and affordable.
  6. 1:09:00 The Culture of Black Hat and DEF CON: A comparison of the professionalized atmosphere of Black Hat versus the community-driven chaos of DEF CON.