# 071 - Snerd Niped Page: https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped Text version: https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md Podcast: [Unnamed Reverse Engineering Podcast](https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753) Published: 2024-09-07T22:24:29+00:00 Episode link: https://unnamedre.com/episode/71 Audio file: https://traffic.libsyn.com/secure/reverseengineering/071_-_Snerd_Niped.mp3?dest-id=552832 Processing state: processed JSON: https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped Duration seconds: 5463 ## Resource Security researcher Thomas Roth (StackSmashing) breaks down his recent hardware reverse engineering exploits on Apple's latest silicon. The discussion covers JTAG access on iPhone 15, USB-C controller vulnerabilities, and low-cost fault injection techniques. ## Highlights - Main idea: Apple's transition to USB-C on iPhone 15 introduced new attack surfaces via the ACE3 controller - Practical takeaway: Low-cost tools like the PicoEMP can be used for effective voltage fault injection without expensive oscilloscopes - Failure mode: Relying on default BitLocker configurations without PINs leaves systems vulnerable to cold boot attacks - Main idea: Reverse engineering the USB-PD communication protocol reveals undocumented behaviors in M-series Macs - Practical takeaway: HexTree.io provides micro-courses to democratize specialized hardware security training ## Topics Hardware Hacking, Reverse Engineering, iPhone 15, Apple Silicon, Fault Injection, USB-C Controller, BitLocker, Embedded Security, JTAG ## Chapters - 8:00 — Analyzing Apple's USB-C Power Delivery: An investigation into the ACE3 controller and how its USB stack differs from documented specifications on iPhone 15 and M-series Macs. - 28:00 — Hardware Fault Injection Techniques: The risks of electromagnetic fault injection (EMFI) and using low-cost tools for side-channel analysis. - 42:00 — Bypassing Windows Disk Encryption: Discussing the feasibility of cold boot attacks to extract BitLocker keys from memory. - 49:00 — Embedded Systems Village at DEF CON: Showcasing accessible hardware hacking boards designed to teach JTAG and glitching to the community. - 56:00 — Democratizing Security Research Tools: How the cost of security research is dropping as specialized hardware becomes more accessible and affordable. - 1:09:00 — The Culture of Black Hat and DEF CON: A comparison of the professionalized atmosphere of Black Hat versus the community-driven chaos of DEF CON. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.