{"podcast":{"title":"Unnamed Reverse Engineering Podcast","slug":"unnamed-reverse-engineering-podcast-752753","podcast_index_feed_id":752753,"rss_url":"https://reverseengineering.libsyn.com/rss","website_url":"https://unnamedre.com","image_url":"https://static.libsyn.com/p/assets/5/2/7/1/52713ee56bbb6ad5/logo1400x1400.png","author":"Alvaro Prieto, Jen Costillo","episode_count":79,"summary":"Listen and learn about different reverse engineering hardware projects and methods as Alvaro (@alvaroprieto) and Jen(@rebelbotjen) talk with guests about their work.","last_synced_at":null,"page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753"},"episode":{"title":"071 - Snerd Niped","slug":"071-snerd-niped","published_at":"2024-09-07T22:24:29+00:00","page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped","show_page_url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753","url":"https://unnamedre.com/episode/71","audio_url":"https://traffic.libsyn.com/secure/reverseengineering/071_-_Snerd_Niped.mp3?dest-id=552832","summary":"Security researcher Thomas Roth (StackSmashing) breaks down his recent hardware reverse engineering exploits on Apple's latest silicon. The discussion covers JTAG access on iPhone 15, USB-C controller vulnerabilities, and low-cost fault injection techniques.","meta_description":"Explore hardware hacking breakthroughs: iPhone 15 JTAG, Apple USB-C controller vulnerabilities, and low-cost fault injection tools with StackSmashing.","key_points":["Main idea: Apple's transition to USB-C on iPhone 15 introduced new attack surfaces via the ACE3 controller","Practical takeaway: Low-cost tools like the PicoEMP can be used for effective voltage fault injection without expensive oscilloscopes","Failure mode: Relying on default BitLocker configurations without PINs leaves systems vulnerable to cold boot attacks","Main idea: Reverse engineering the USB-PD communication protocol reveals undocumented behaviors in M-series Macs","Practical takeaway: HexTree.io provides micro-courses to democratize specialized hardware security training"],"chapters":[{"start_ms":480000,"title":"Analyzing Apple's USB-C Power Delivery","summary":"An investigation into the ACE3 controller and how its USB stack differs from documented specifications on iPhone 15 and M-series Macs."},{"start_ms":1680000,"title":"Hardware Fault Injection Techniques","summary":"The risks of electromagnetic fault injection (EMFI) and using low-cost tools for side-channel analysis."},{"start_ms":2520000,"title":"Bypassing Windows Disk Encryption","summary":"Discussing the feasibility of cold boot attacks to extract BitLocker keys from memory."},{"start_ms":2940000,"title":"Embedded Systems Village at DEF CON","summary":"Showcasing accessible hardware hacking boards designed to teach JTAG and glitching to the community."},{"start_ms":3360000,"title":"Democratizing Security Research Tools","summary":"How the cost of security research is dropping as specialized hardware becomes more accessible and affordable."},{"start_ms":4140000,"title":"The Culture of Black Hat and DEF CON","summary":"A comparison of the professionalized atmosphere of Black Hat versus the community-driven chaos of DEF CON."}],"topics":["Hardware Hacking","Reverse Engineering","iPhone 15","Apple Silicon","Fault Injection","USB-C Controller","BitLocker","Embedded Security","JTAG"],"duration_seconds":5463,"processing_state":"processed","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/071-snerd-niped/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/071-snerd-niped.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}