519: The Password Is All Zeros
Embedded23 Jan

519: The Password Is All Zeros

Mark Omo and James Rowley spoke with us about safecracking, security, and the ethics of doing a bad job.

Mark and James gave an excellent talk on the development of their safecracking tools at DEF CON 33: Cash, Drugs, and Guns: Why Your Safes Aren't Safe. It included a section of interaction involving the lock maker's lawyers bullying them and how the Electronic Frontier Foundation (EFF) has a Coders' Rights Project to support security research.

As mentioned in the show, the US Cyber Trust Mark baseline has a very straightforward checklist; NISTIR 8259 is the overall standard, NISTIR 8259A is the technical checklist, NISTIR 8259B is the non-technical (process/maintenance) checklist. Roughly the process is NISTIR 8259 -> Plan/Guidance; NISTIR 8259A -> Build; NISTIR 8259B -> Support.

We discussed ETSI EN 303 645 V3.1.3 (2024-09) Cyber Security for Consumer Internet of Things: Baseline Requirement and the EU's CRA: Cyber Resilience Act which requires manufacturers to implement security by design, have security by default, provide free security updates, and protect confidentiality. See more here: How to prepare for the Cyber Resilience Act (CRA): A guide for manufacturers.

We didn't mention Ghidra in the show specifically, but it is a tool for reverse engineering software: given a binary image, what was the code?

Some of the safecracking was helped by the lock maker using the same processor in the PS4 which has many people looking to crack it. See fail0verflow :: PS4 Aux Hax 1: Intro & Aeolia for an introduction.

Mark and James have presented multiple times at Hardwear.io, a series of conferences and webinars about security (not wearables). Some related highlights:

Episoder(569)

498: To Consume Stickers

498: To Consume Stickers

At the end of this week's show, Elecia reads a Winnie the Pooh poem as Cookie Monster death metal. Before that, Chris and Elecia chat about mental health, journaling, personal projects, and listener q...

4 Apr 20251h 6min

497: Everyone Likes Tiny

497: Everyone Likes Tiny

OpenMV has a new Kickstarter so CEO Kwabena Agyeman chatted with us about more powerful (and smaller!) programmable cameras. See OpenMV's site for their existing cameras. See their (already funded!)...

20 Mar 20251h 24min

496: Beauty, Elegance, Consistency

496: Beauty, Elegance, Consistency

Professor Shimon Schocken spoke with us about teaching computer science from NAND logic gates to arithmetic units, micro assembly, virtual machines, compilers, operating systems, and the Tetris games....

6 Mar 202559min

495: Shortcut the Difficulties of Reality

495: Shortcut the Difficulties of Reality

Professor Cindy Harnett spoke to us about new and different sensors and actuators, primarily designed for soft robotics and fabricated with relatively low cost materials. Cindy is a professor of elect...

21 Feb 20251h 1min

494: All Tech Is Wearable

494: All Tech Is Wearable

Debra Ansell joined us to talk about finding friends and exchanging neat gifts, accidentally tricking people into making unmanufacutable boards, and happy, blinking lights. Debra is usually known by t...

7 Feb 20251h 15min

493: Put the Peeps in the Chili Pot

493: Put the Peeps in the Chili Pot

Elecia and Chris talk with each other about the state of Chris' mind, what makes an embedded developer stand out, "LEGO block" based design, unit tests, and astronomy. Whew! Elecia was recently on the...

24 Jan 20251h 20min

492: Octopus Army

492: Octopus Army

Nathan Jones chatted with us about his proposal for a computer architecture book based on a 4-bit computer. Nathan found the 4-bit computer in the Hackaday SuperCon 2022 badge and was amazed by some...

27 Des 20241h 9min

491: Oscillators Oscillating Other Oscillators

491: Oscillators Oscillating Other Oscillators

Chris and Elecia spoke with Kirk Pearson about running audio-electronic-art workshops, interesting sounds, and their book Make: Electronic Music from Scratch: A Beginner's Guide to Homegrown Audio Gi...

13 Des 20241h 6min

Populært innen Vitenskap

fastlegen
rekommandert
jss
tingenes-tilstand
liberal-halvtime
sinnsyn
rss-rekommandert
forskningno
tomprat-med-gunnar-tjomlid
rss-nysgjerrige-norge
villmarksliv
dekodet-2
fjellsportpodden
rss-paradigmepodden
smart-forklart
kvinnehelsepodden
tidlose-historier
nevropodden
utenrikshospitalet
rss-lundqvist-podden