
In this podcast, we discuss various aspects of security with non-hearsay people familiar with this area of activity. In general, it turned out quite informative issue on this subject. It all starts with a discussion of how to start diving this area from the very beginning and ending with the reversing of the chips. We tried to discuss a large number of areas of hardware security and made a list of all the topics discussed with additional references and other materials for in-depth study.
Participants:Alexander Matrosov (
@matrosov )
Dmitry Nedospasov (
@nedos)Oleg Kupreev (
@ 090h )
Alexander Bazhanyuk (
@ABazhaniuk )
Dmitry Oleksyuk (
@d_olex )
')
MP3 filePodcast official siteGithub c show notesXboxLiterature: Hacking the Xbox [
pdf ]
WP: XBMCXecuter ModchipsTUB - Security in TelecommunicationsChaos Communications CongressRecon20132014Vulnerabilities of various systemsWP: EMV
WP: PayTV / Conditional AccessWP: Workflow
WP: Failure AnalysisDe gate
WP: Confocal MicroscopeWP: Netlist
WP: RegistersChip typesWP: ASICWP: VLSILiterature: Weste [CMOS VLSI DesignWP: FPGAHdlVerilogVhdlLiterature:
Verilog vs. HDL - HDL Chip DesignAVRAVR instruction setAVR GCCSimple tulzaDP Bus pirateArduinoEmbedded ProtocolsWP: UARTWP: I2CWP: SPIMichael Ossmann (
@michaelossmann )
KS: @mossmannDaishoIntdoucing DaishoAgilent / Keysight / HPWP: AgilentTeledyne / LeCroy
Tektronix
Rhode schwarzPCI Express Protocol AnalyzerFpga devboardsXilinx Spartan 6 SP605Xilinx Virtex 6 ML605Xilinx Vivado Design SweetXilinx Chipscope ProTerasic DE0-nano (Recommended !!!)
Microsemi Igloo 2 Evaluation Kit (Recommended !!!)
Distributors:DigikeyMouserFarnellAvnetKernel developmentXilinx IPOpen coresWorking AES - Avalon AESTulzyDP ATX breakoutFTDI USB / UARTWP: Microchip PICDp cool runnerGlitching ddkStudent (
@rgsilva )
https://github.com/rgsilva/ddk-armhttps://github.com/rgsilva/ddk-fpgaPower anlaysisTimo Kasper "
Milking the Digital Cashcow (29c3) "
Literature: Stefan Mangard,
Power Analysis Attacks: Revealing the Secrets of Smart CardsMicroprobing / data manipulationReport: Chris Tarnovsky (
@semiconduktor )
Inducing Momentary Secure Secure Cards (DEF CON 16)Article:
Sorcer's Apprentice Guide to Fault AttacksArticle: Oliver Kömmerling,
Design Principles for Tamper-Resistant Smartcard ProcessorsLiterature: Ross Anderson,
Security Engineering - Chapter 16: Physical Tamper ReistanceArticle:
Poc or GTFO 0x01 - Burning a phoneISO7816Die Datenkeke - DDK @DieDatenkrakeThorsten Schröder (
@ br3t )
WP: SDRKeykerikiNordic SemiUSRPParallel computing systemsWP: Parallel ComputingWP: pthreadWP: PipelineChip obfuscationObfuscated Gates - SypherMedia InternationalHacking ChipsReport: Olivier Thomas (
@reivilo_t ),
Hardware Reverse-engineering Tools (REC0N 2013)Report: Dmitry Nedospasov (
@nedos ),
Security of the IC Backside (30c3)Report: Chris Tarnovsky (
@semiconduktor ),
Semiconductor Security Awareness Today and Yesterday (Blackhat 2010)BBC Panorama -
Murdoch's TV PiratesLiterature:
Murdoch's PiratesBaseband / DSPWP: DSPWP: Baseband ProcessorRalf-Philipp Weinmann (
@esizkur ),
Baseband Exploitation in 2013Analog devices blackfinWP: VLIWWP: Floating Point UnitWP: MicrocodeRFHabr:
Hacker-friendly Software-defined radioOsmocom RTL SDRDPS FMHackrfKS: HackRFHackRF trainingBladeRFUbertooth oneThe Amphour: An Interview with Michael OssmannKicadCern kicadARM TrustzoneChris TarnovskyChris has a great two-day training on
Toorcon.Flylogic BlogWired:
How to Reverse-Engineer a Satellite TV Smart CardTwitter:
@semiconduktorWP: Electron MicroscopeWhat is needed from the tools and tools in order to begin to delve into the topic in practice?As for the equipment, I highly recommend watching:
EEVBlogFor starters, you can go to the Heckspace
<100 €DP Bus pirateArduinoBreadboard
cheap multimeter
DP ATX Breakout Board<500 €Multimeter (Extech, Amprobe, BK Precision)
Logic Analyzer (
Saleae )
Soldering station (with smoldered pins)
<1500 €Oscilloscope (
Rigol DS2072 )
=> This model was hacked - you can turn on all features in the software with
a key generator that is somewhere hereRework station (hot-air belt station)
FPGA Devboard (Terasic DE0-nano)
<2500 €Serious Multimeter (Fluke 87V)
second zone station
<5000 €4-channel oscilloscope
second "gray" multimeter (for example Agilent OLED)
No chapel (equipment for serious people)LPKF Protomat s63Ultratec ASAP-1Teledyne LeCroy 7-ZiRiscure Laser StationKarl Suss Probing Station
Karl Suss PH 150Pico probeNew Wave Research EZLazeHamamatsu phemosFEI FIB