519: The Password Is All Zeros
Embedded23 Jan

519: The Password Is All Zeros

Mark Omo and James Rowley spoke with us about safecracking, security, and the ethics of doing a bad job.

Mark and James gave an excellent talk on the development of their safecracking tools at DEF CON 33: Cash, Drugs, and Guns: Why Your Safes Aren't Safe. It included a section of interaction involving the lock maker's lawyers bullying them and how the Electronic Frontier Foundation (EFF) has a Coders' Rights Project to support security research.

As mentioned in the show, the US Cyber Trust Mark baseline has a very straightforward checklist; NISTIR 8259 is the overall standard, NISTIR 8259A is the technical checklist, NISTIR 8259B is the non-technical (process/maintenance) checklist. Roughly the process is NISTIR 8259 -> Plan/Guidance; NISTIR 8259A -> Build; NISTIR 8259B -> Support.

We discussed ETSI EN 303 645 V3.1.3 (2024-09) Cyber Security for Consumer Internet of Things: Baseline Requirement and the EU's CRA: Cyber Resilience Act which requires manufacturers to implement security by design, have security by default, provide free security updates, and protect confidentiality. See more here: How to prepare for the Cyber Resilience Act (CRA): A guide for manufacturers.

We didn't mention Ghidra in the show specifically, but it is a tool for reverse engineering software: given a binary image, what was the code?

Some of the safecracking was helped by the lock maker using the same processor in the PS4 which has many people looking to crack it. See fail0verflow :: PS4 Aux Hax 1: Intro & Aeolia for an introduction.

Mark and James have presented multiple times at Hardwear.io, a series of conferences and webinars about security (not wearables). Some related highlights:

Episoder(569)

514: Just Turn Off All the Computers

514: Just Turn Off All the Computers

Philip Koopman joined us to talk about embedded systems becoming embodied and intelligent. We focus on the safety considerations of making an intelligent and embodied device.  Phil's new book is Embo...

14 Nov 20251h 10min

513: I'm Sorry You Learned Something

513: I'm Sorry You Learned Something

Jason Turner of C++ Weekly and Empty Crate spoke with us about the joy of puzzles, the changing directions of an interesting career, and the C++ programming language. I mean, of course we talked about...

30 Okt 20251h 17min

512: What if I Didn't Stop?

512: What if I Didn't Stop?

Katherine "Smalls" Connell spoke with us about making thin and flexible circuits, making stretchable electronics, and running a successful Kickstarter. Katherine's Kickstarter: Sprite Lights LED Body...

16 Okt 20251h 5min

511: Forty Trillion Divides

511: Forty Trillion Divides

Chris and Elecia talk about the show overflowing to another bit, fight over vim vs nano, consider awards, discuss writing (and self-motivation), consider linear algebra on AI cores, encourage remote d...

2 Okt 20251h 22min

510: The Secret Chip

510: The Secret Chip

Christina Cyr spoke with us about building cell phones, entrepreneurship, social purpose corporations, awards, lithium recycling, and her interesting career path. We talked about Christina's Cyrcle P...

19 Sep 20251h 4min

509: Swarmed by Engineers

509: Swarmed by Engineers

Steve Hinch wrote a book about engineering, innovation, and business. He shares decades of wisdom gleaned from his career at Hewlett-Packard and Agilent as an engineer, manager, marketing director, an...

5 Sep 20251h 13min

508: Descartes' Demon

508: Descartes' Demon

William Griffin spoke to us about hardware-in-the-loop testing, simulation, terminology, learning complex topics, and books. We don't usually expand upon the show title but Wikipedia has a rabbit hole...

21 Aug 20251h 22min

507: Turn Our Data Into Predators

507: Turn Our Data Into Predators

Chris and Elecia chat about books, courses, alternate podcasts, electronics, statistics, kidnapping Roo, and journaling failures. The Embedded Patreon book club is reading Data-Driven Science and Eng...

7 Aug 20251h 14min

Populært innen Vitenskap

fastlegen
rekommandert
tingenes-tilstand
sinnsyn
forskningno
rss-rekommandert
liberal-halvtime
smart-forklart
jss
tomprat-med-gunnar-tjomlid
villmarksliv
fjellsportpodden
rss-paradigmepodden
dekodet-2
pod-britannia
psykopoden
rss-overskuddsliv
tidlose-historier
aldring-og-helse-podden
nevropodden