{"podcast":{"title":"Unnamed Reverse Engineering Podcast","slug":"unnamed-reverse-engineering-podcast-752753","podcast_index_feed_id":752753,"rss_url":"https://reverseengineering.libsyn.com/rss","website_url":"https://unnamedre.com","image_url":"https://static.libsyn.com/p/assets/5/2/7/1/52713ee56bbb6ad5/logo1400x1400.png","author":"Alvaro Prieto, Jen Costillo","episode_count":79,"summary":"Listen and learn about different reverse engineering hardware projects and methods as Alvaro (@alvaroprieto) and Jen(@rebelbotjen) talk with guests about their work.","last_synced_at":null,"page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753"},"episode":{"title":"061 - A Case of the Sniffles","slug":"061-a-case-of-the-sniffles","published_at":"2022-11-09T05:54:24+00:00","page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/061-a-case-of-the-sniffles","show_page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753","url":"https://reverseengineering.libsyn.com/061-a-case-of-the-sniffles","audio_url":"https://traffic.libsyn.com/secure/reverseengineering/061_-_A_Case_Of_The_Sniffles.mp3?dest-id=552832","summary":"A deep dive into Bluetooth Low Energy (BLE) security, focusing on the development of the Sniffle tool and the mechanics of relay attacks. Guest Sultan Qasim Khan explains how low-level sniffing reveals firmware bugs and vulnerabilities in proximity-based authentication.","meta_description":"Explore BLE reverse engineering, the Sniffle sniffer tool, and how relay attacks bypass car security systems with Sultan Qasim Khan.","key_points":["Main idea: Low-level BLE sniffing is essential for debugging firmware bugs that higher-level stack captures miss","Practical takeaway: Using tools like Sniffle with Wireshark plugins allows for real-time analysis of Bluetooth 5 features","Failure mode: Relay attacks can trick proximity-based systems, like car key fobs, by forwarding signals between a legitimate key and a target","Technical insight: Modern defenses against relay attacks include implementing distance-bounding or time-of-flight ranging checks","Lesson: Security vulnerabilities are frequently found in the less-traveled, unexamined parts of a protocol implementation"],"chapters":[{"start_ms":60000,"title":"Introduction and Background","summary":"Sultan Qasim Khan discusses his transition from software development to reverse engineering via Linux driver porting."},{"start_ms":300000,"title":"The Origins of Sniffing","summary":"A look at the early tools used for USB and Bluetooth analysis and the challenges of hardware-level debugging."},{"start_ms":600000,"title":"Improving Ubertooth Firmware","summary":"Addressing limitations in channel mapping and firmware capabilities for better packet capture."},{"start_ms":840000,"title":"The Sniffle Toolset","summary":"How Sniffle provides support for high-bitrate BLE and integrates with Wireshark for protocol analysis."},{"start_ms":1140000,"title":"Decoding the BLE Stack","summary":"The technical difficulties of handling preambles, access addresses, and simultaneous transmissions."},{"start_ms":1680000,"title":"IoT Provisioning Vulnerabilities","summary":"How BLE is used in IoT setup processes and the risks of firmware bugs in integrated controllers."},{"start_ms":1920000,"title":"Mechanics of Relay Attacks","summary":"An explanation of how attackers bypass proximity authentication in cars and smart locks."},{"start_ms":2220000,"title":"Defending Against Proximity Fraud","summary":"Discussing ranging checks and hardware-level solutions to prevent signal forwarding attacks."}],"topics":["Bluetooth Low Energy","Reverse Engineering","Cybersecurity","Relay Attacks","IoT Security","Packet Sniffing","Firmware Analysis","Protocol Security"],"duration_seconds":3600,"processing_state":"processed","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/061-a-case-of-the-sniffles/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/061-a-case-of-the-sniffles.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}