{"podcast":{"title":"Unnamed Reverse Engineering Podcast","slug":"unnamed-reverse-engineering-podcast-752753","podcast_index_feed_id":752753,"rss_url":"https://reverseengineering.libsyn.com/rss","website_url":"https://unnamedre.com","image_url":"https://static.libsyn.com/p/assets/5/2/7/1/52713ee56bbb6ad5/logo1400x1400.png","author":"Alvaro Prieto, Jen Costillo","episode_count":79,"summary":"Listen and learn about different reverse engineering hardware projects and methods as Alvaro (@alvaroprieto) and Jen(@rebelbotjen) talk with guests about their work.","last_synced_at":null,"page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753"},"episode":{"title":"055 - Stacks Of Bricked Chips","slug":"055-stacks-of-bricked-chips","published_at":"2022-03-13T18:27:23+00:00","page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/055-stacks-of-bricked-chips","show_page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753","url":"https://unnamedre.com/episode/55","audio_url":"https://traffic.libsyn.com/secure/reverseengineering/055_-_Stacks_Of_Bricked_Chips.mp3?dest-id=552832","summary":"Laura Abbott from Oxide Computer details her discovery of a privilege escalation vulnerability in NXP's Arm TrustZone-M implementation. The discussion covers the technical process of reverse engineering ROM patches and the challenges of coordinated disclosure with hardware vendors.","meta_description":"Explore the reverse engineering of Arm TrustZone-M, uncovering vulnerabilities in NXP's ROM patch and the complexities of hardware security research.","key_points":["Main idea: Vulnerabilities in hardware ROM patches can break the fundamental security assumptions of Arm TrustZone-M","Practical takeaway: Using Ghidra and SVD loaders can help reconstruct hardware register access during reverse engineering","Failure mode: Relying on vendor-provided security settings without verifying the underlying hardware implementation can lead to broken trust chains","Technical insight: Code golfing Arm assembly is a useful technique for developing minimal, impactful proofs of concept","Lesson learned: Documentation, including obscure spreadsheets attached to PDFs, is often the most undervalued tool in a researcher's arsenal"],"chapters":[{"start_ms":60000,"title":"The Future of Systems Programming","summary":"A discussion on the transition from C to Rust in kernel development and the promise of memory-safe languages for microcontrollers."},{"start_ms":360000,"title":"Establishing a Root of Trust","summary":"Exploring the difficulty of verifying exactly what software is running on a system and building a verifiable chain of trust."},{"start_ms":600000,"title":"Reverse Engineering with Ghidra","summary":"How the researcher utilized Ghidra and existing projects to begin analyzing hardware firmware."},{"start_ms":900000,"title":"Analyzing the ROM Patch","summary":"A deep dive into reviewing the ROM patch functionality and identifying potential bugs in the immutable code."},{"start_ms":1440000,"title":"Demonstrating Privilege Escalation","summary":"The process of creating a proof of concept to show the ability to read secure registers from a non-secure state."},{"start_ms":1740000,"title":"Code Golfing for Exploitation","summary":"Using minimal instruction sets to demonstrate the bypass of hardware security boundaries."},{"start_ms":2280000,"title":"Tooling and Research Methodology","summary":"Discussing the use of SVD loaders, register allocation, and the importance of technical documentation."}],"topics":["Reverse Engineering","Arm TrustZone-M","NXP Semiconductors","Ghidra","Rust Programming","Linux Kernel","Hardware Security","Privilege Escalation","Firmware Analysis"],"duration_seconds":3717,"processing_state":"processed","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/055-stacks-of-bricked-chips/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/055-stacks-of-bricked-chips.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}