Episode
074 - This Coconut Won't Open
- Published
- May 6, 2025
- Duration seconds
- 3903
- Processing state
processed- Canonical source
- https://unnamedre.com/episode/74
- Audio
- https://traffic.libsyn.com/secure/reverseengineering/074_-_This_Coconut_Wont_Open.mp3?dest-id=552832
Actions
POST https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/074-this-coconut-won-t-open/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/074-this-coconut-won-t-open.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Members of the Michigan Tech Red Team discuss the technical challenges of reverse engineering electronic access control systems. The conversation explores vulnerabilities in RFID locks and the specialized hardware used to audit physical security.
Topics
- Reverse Engineering
- Access Control
- RFID Security
- Hardware Hacking
- Physical Security
- Proxmark3
- Red Teaming
- Electronic Locks
Highlights
- Main idea: The Michigan Tech Red Team uses hardware auditing to uncover vulnerabilities in digital and physical access control systems
- Practical takeaway: Tools like the Proxmark3 and Chameleon Ultra are essential for emulating RFID cards and interrogating lock protocols
- Failure mode: Relying on trade secrets instead of patents can leave hardware vulnerabilities unaddressed and harder to patch
- Technical detail: Handheld programmers are used to synchronize time and manage emergency keys for electronic locks
- Research goal: Developing lightweight, portable applications for keychain-sized devices to demonstrate potential physical security impacts
Chapters
1:00The Access Control Village: Introduction to the Michigan Tech Red Team and their role running the Access Control Village at CypherCon and SecretCon.6:00Origins in Hardware Reversing: How interest in RFID cards and hardware internships led to specialized research in access control.16:00Developing Proxmark Tools: Discussion on creating tools for the Proxmark3 to parse fields and manipulate RFID data.25:00Lock Re-keying and Research Goals: Reflections on physical lock maintenance and the future direction of their security research.40:00Emulation and Hardware Interrogation: How devices like the Chameleon Ultra emulate cards and time-set functions to audit locks.45:00Patents vs. Trade Secrets: The security implications of companies choosing trade secrets over patents for hardware components.59:00Essential Tooling and Community: Recommendations for the Iceman fork of Proxmark and connecting with the security research community.