[00:01.080 --> 00:07.880] What we have is Exploiting Zigbee and the Internet of Things by my neighbor and yours, Travis Goodspeed. [00:12.980 --> 00:13.620] Howdy, y'all. [00:14.920 --> 00:18.080] So if you're here to learn about politics or law, you're in the wrong room. [00:19.670 --> 00:22.460] If you'd like to, I can include some, even though I don't know any. [00:23.860 --> 00:30.640] If you want to keep up to date on political news, there's this lovely Twitter account called Real Time World War II, and it's awesome. [00:30.640 --> 00:38.540] Everything they say is accurate, there's no political bias, and I just can't understand why they're not getting these massive angry retweets. [00:39.060 --> 00:46.740] I mean, they're reporting about how Germany just floods into France after doing fake peace agreements, and no one seems to give a shit. [00:48.720 --> 00:50.880] But I tend to see things a bit differently. [00:53.520 --> 00:57.320] There are lots of people that I need to thank in the line of my Zigbee research. [00:57.320 --> 01:04.860] This is sort of condensing it all and giving you the ways in which I break a number of wireless sensors. [01:05.960 --> 01:07.930] Or it's called the Internet of Things. [01:08.150 --> 01:14.600] It's one of these technologies that has a million different buzzwords for it, none of which are actually used consistently in the field. [01:14.790 --> 01:25.880] So you'll go in and you'll see this parking sensor, or a thermometer on a gas vent, or whatever weird thing you can imagine. [01:25.880 --> 01:32.460] Someone has built a wireless sensor with it, and they call it the thing that it is, like a parking sensor or a gas vent. [01:32.860 --> 01:35.720] And they don't call it by any consistent technological name. [01:36.160 --> 01:46.240] The closest would be Zigbee, or the lovely short monosyllabic IEEE 802.15.4. [01:47.360 --> 01:49.480] But all of these things get skewed around. [01:49.940 --> 01:57.660] And in the course of this research, I've gotten some neighborly help from Michael Osmond, from Mike Kershaw, better known as Dragorn, who's the guy who started Kismet. [01:58.680 --> 02:02.290] And he's got some new Zigbee research of his own that's worth looking into. [02:03.490 --> 02:05.740] And the Scooby crew up at Dartmouth. [02:06.680 --> 02:08.380] There's all sorts of good neighbors up there. [02:10.560 --> 02:15.160] Now, when you have things on the Internet, you have all of these features about them that we're familiar with. [02:15.440 --> 02:18.620] But that if you look at the older HOPE videos that came out... [02:19.520 --> 02:20.120] What was it? [02:20.160 --> 02:24.110] Six months ago, they started streaming the talks from the 1994 HOPE. [02:25.080 --> 02:29.520] And one of the things that you noticed was that ubiquitous data access didn't exist back then. [02:30.440 --> 02:35.150] In the 1994 talks, they started talking about, you know, sniffing cell phones. [02:35.270 --> 02:38.340] And they were doing it by using a ham radio. [02:39.380 --> 02:42.680] Because that's how primitive cell phone technology was in 1994. [02:44.020 --> 02:48.380] And similarly, this technology is just barely beginning to be deployed. [02:49.100 --> 02:52.820] The chips only became available six, seven years ago. [02:53.280 --> 02:55.240] And they weren't deployed until recently. [02:55.240 --> 02:59.240] And even then, they're getting deployed in a very ad hoc manner. [03:00.340 --> 03:03.740] So while on the Internet, you've got everything accessible worldwide. [03:03.960 --> 03:06.560] Even if not on the inbound end, at least on the outbound end. [03:06.720 --> 03:11.740] Like, if you're on a laptop that's behind a wireless router, the world might not be able to directly connect to you. [03:11.920 --> 03:13.300] But you can directly connect to the world. [03:14.340 --> 03:16.240] You also have standard protocols on the Internet. [03:17.140 --> 03:19.900] Everything seems to be switching toward running over HTTP. [03:20.640 --> 03:27.580] And the few other protocols that have survived have only done so because of peer-to-peer or performance reasons. [03:28.600 --> 03:30.740] You also... and in this... [03:33.140 --> 03:41.540] On this Internet equipment, on laptops and on cell phones and on the rest of that, you have very, very little variety. [03:42.160 --> 03:43.360] TCP/IP 1. [03:44.420 --> 03:49.740] I can't see you if you raise your hands, but has anyone here used IPX, SPX in the past? [03:50.520 --> 03:50.960] Okay. [03:51.320 --> 03:52.640] Have any of you used it this year? [03:55.680 --> 04:00.060] See, I've used a PDP-11 this year, and it was only for novelty's sake. [04:00.260 --> 04:07.480] And all of those other networking protocols are just as dead in modern big computers. [04:07.620 --> 04:09.040] But in little computers, they're still around. [04:10.140 --> 04:15.050] So the Internet of things, we have very low power radios and very low power microcontrollers. [04:16.160 --> 04:21.760] And if you choose your battery right, which I did not, you get very long battery life. [04:24.850 --> 04:30.670] Speaking of which, if you have... we'll get back to that in a bit. [04:31.620 --> 04:33.480] Also on the Internet of things, you have infinite diversity. [04:34.290 --> 04:37.820] If you're making something for the Internet, it has to do HTTP. [04:38.520 --> 04:42.560] And we're fast approaching the point where, God forbid, it's going to have to speak Facebook. [04:45.170 --> 04:47.670] I can't wait until it goes the way of dig.com. [04:48.520 --> 04:50.620] That's going to be icing on the cake. [04:50.970 --> 04:55.300] I know, I know, they're already worthless, but I'd like the stock market to catch up with that. [04:57.620 --> 04:58.480] Just for that stock. [04:58.480 --> 05:02.800] I mean, there are plenty of other companies that actually, like, build things and help people. [05:05.300 --> 05:08.230] So you also have, like... [05:09.000 --> 05:13.540] The limitation on file layer protocols is enforced by who manufactures the chips. [05:14.910 --> 05:20.140] And there are fewer people manufacturing chips than there are actually building these products. [05:20.470 --> 05:29.240] So even though every one of these products is designed as a sort of one-off by the firm that manufactures it, they use standard chips. [05:29.680 --> 05:37.300] And that means that even though there are a lot of file layer protocols, it's a lot on the order of 10 or 20, which is manageably small. [05:38.140 --> 05:40.440] And some of these you can promiscuously sniff. [05:40.860 --> 05:42.580] Others you cannot, but some you can. [05:43.820 --> 05:48.200] And when you sniff them, then you can figure out the upper layer protocols yourself. [05:48.840 --> 05:54.620] There are far more layer two protocols, but these are restricted by the number of library vendors. [05:55.340 --> 06:04.820] In that if I'm making my own wireless sensor network, I will probably use a library or at least a layer two protocol that someone else developed. [06:05.280 --> 06:14.620] And then for layer three and up, everything I do is going to be awkward and unique and utterly incompatible with what everyone else did. [06:16.480 --> 06:22.480] This has created all sorts of consumer electronics confusion in the accessories that were supposed to go out for the smart grid. [06:22.740 --> 06:28.600] So for a while it looked as if you would be able to buy a magic thermostat that could then talk to your electric meter. [06:29.160 --> 06:39.480] The problem is that Walmart and similar companies, Amazon.com, no one wants to advertise something that's only going to work in your little slice of eastern Kentucky. [06:40.420 --> 06:42.400] So these products never took off. [06:42.660 --> 06:46.300] They were manufactured, they were designed, and a lot of companies lost a lot of money on it. [06:46.600 --> 06:51.380] Not nearly so much money as the social networking companies, but still plenty. [06:52.200 --> 06:55.480] And the end hardware is like the badge that came out two years ago. [06:56.740 --> 07:01.880] When I designed this badge, I began with a protocol that Milos Mariak designed. [07:01.880 --> 07:07.240] And I rewrote the firmware to run in the MSP430 chip, which is more powerful. [07:07.540 --> 07:11.200] But I used the same radio, and the two are largely compatible. [07:11.740 --> 07:17.400] You can use the Next HOPE badge with a USB attachment to packet sniff Milos's packets. [07:17.660 --> 07:23.540] And you can even run a lot of compatible devices across the two. [07:23.540 --> 07:34.420] Now, what you can't do, though, is you can't, by looking at the box, know that his technology and mine are roughly the same thing. [07:34.720 --> 07:37.520] You actually have to lift it apart and read the part numbers. [07:37.740 --> 07:40.460] You have to know that the big chip is an MSP430. [07:40.680 --> 07:43.220] You have to know that the little chip is a Nordic RF radio. [07:44.280 --> 07:54.960] The Nordic RF radio is also used in the Microsoft wireless keyboards, which is great because they use this very advanced form of cryptography called exclusive OR. [07:58.910 --> 08:01.170] And the key is something very hard to find. [08:01.270 --> 08:01.990] It's the MAC address. [08:03.490 --> 08:07.490] So every packet includes the key at least once by default in its MAC address. [08:07.850 --> 08:17.290] And then in a USB keyboard event, when you have a key up, like if you press down the letter J, then it sends a list which includes the letter J and a bunch of empty spaces. [08:17.290 --> 08:21.330] And then when your key goes up, it has the same list but without the letter J. [08:21.730 --> 08:23.070] That's a lot of zeros. [08:23.450 --> 08:28.590] And what happens when you exclusive OR 13 zeros in a row with a 5-byte MAC address? [08:30.510 --> 08:32.550] And these MAC addresses are 5 bytes. [08:33.170 --> 08:38.930] They are... unlike in the PC world, which is standardized on 6, in the embedded world, everything is different. [08:39.950 --> 08:43.530] And these radios make it double as what's called the start of frame delimiter. [08:43.530 --> 08:48.850] So promiscuously sniffing the keyboards from this badge was a significant accomplishment. [08:49.210 --> 08:51.350] It was not something easy or predictable. [08:51.750 --> 08:56.330] And so when... I'm going off on a tangent here, but it's a good tangent. [08:57.210 --> 09:03.930] When Max Moser and Torsten Schroeder went to Microsoft and they said, hey, we've built this thing called the Kikariki, which can sniff your wireless keyboard. [09:04.550 --> 09:07.830] Microsoft said, oh, we don't care because you need to build custom hardware. [09:09.550 --> 09:14.430] And they had a picture of this badge in their slide saying that, you know, you couldn't use this hardware to do it. [09:14.670 --> 09:17.830] So I fixed... filled the gap. [09:19.510 --> 09:24.590] And the way that you do it is that you have to disable checksumming and trick the radio into receiving background noise. [09:25.810 --> 09:30.670] There's an article on it called Promiscuity is the NRF 24L01 Plus's Duty. [09:31.650 --> 09:35.130] And of course, with a title like that, you'd never imagine that it's something technical. [09:37.390 --> 09:40.930] Like, oh, damn it, this is one of those blogs that just links to another cap picture. [09:43.910 --> 09:45.710] This here is the Zalersha Z1. [09:46.250 --> 09:48.030] It's by a Spanish company. [09:49.450 --> 09:51.990] And I really like this company. [09:52.150 --> 09:59.470] It's like a... I think it's a small group, but they don't call themselves a startup because they ship a product. [10:00.530 --> 10:01.010] And... [10:04.170 --> 10:05.830] You can see it here in this photo. [10:06.030 --> 10:07.770] I mean, this is a really little circuit board. [10:09.010 --> 10:10.670] That's a bill beneath it. [10:11.310 --> 10:12.510] Qatar dinar, I think. [10:12.650 --> 10:15.370] Although I forget the value. [10:16.130 --> 10:19.510] In any case, this contains the essential parts of it. [10:19.610 --> 10:21.690] You need a microcontroller. [10:22.370 --> 10:23.450] You need a radio. [10:23.450 --> 10:25.450] And you need some... [10:26.390 --> 10:27.530] You need something to do. [10:27.990 --> 10:30.150] So, in this case, it's a development kit. [10:30.330 --> 10:32.410] And the something that you do is your own responsibility. [10:32.870 --> 10:35.230] It has little sensor pods that go into the side. [10:35.450 --> 10:37.230] So you can slap a battery pack on one of these. [10:37.430 --> 10:38.950] Put it by, say, a steam trap. [10:39.230 --> 10:44.070] And then you know the temperature by the steam trap, which might give you an idea of how much heat is being lost. [10:44.410 --> 10:47.190] Or whatever else you're interested in. [10:47.310 --> 10:48.590] And it's usually things like that. [10:48.590 --> 10:51.230] It's usually really industrial things. [10:51.970 --> 10:58.790] That if you're not part of that industry, or if you're not interested in messing with that industry, you wouldn't care about. [11:00.490 --> 11:05.570] So, even though very few of us care about steam traps, maybe you'd have a reason to care. [11:05.750 --> 11:07.930] Or maybe you become responsible for a steam trap. [11:08.110 --> 11:17.750] Or maybe you want to make it look like, you know, such and such is the least energy wasteful building in the world fraudulently. [11:17.750 --> 11:19.430] Well, this helps you do all of that. [11:21.830 --> 11:24.950] So for today, I'm going to show you how to find the Internet of Things. [11:25.270 --> 11:26.990] Because these networks are local. [11:27.170 --> 11:29.530] Even though it's called the Internet of Things, it's not actually on the Internet yet. [11:30.770 --> 11:33.930] And when it's attached, it's by a gateway that is largely useless. [11:34.990 --> 11:36.790] Well, useless for the attacker. [11:37.650 --> 11:44.530] But the fun part about this lecture is that I'm going to show you how to extract keys and firmware from the different types of hardware that's used in this network. [11:44.530 --> 11:57.410] And I'm going to show it to you in very concrete examples in the case of exactly how a particular vendor screwed up and how that vendor's customers have their intellectual property exposed because of this. [11:57.570 --> 11:58.950] And also their keys. [12:00.770 --> 12:05.830] The first attack I'm going to show you is against a chip called the ChipCon2420. [12:05.830 --> 12:08.690] And this was a very early chip. [12:09.030 --> 12:10.450] And I love this chip. [12:10.630 --> 12:11.470] It's very reliable. [12:15.150 --> 12:16.990] I recommend this chip to other people. [12:17.130 --> 12:22.550] But it does have the problem that it does the encryption instead of allowing the host machine to do it. [12:23.750 --> 12:26.210] Which is a problem because the keys have to get into the radio. [12:26.430 --> 12:28.650] And they come in through the microcontroller. [12:28.650 --> 12:30.590] And you can watch that happen. [12:30.730 --> 12:31.430] And then you have the keys. [12:33.530 --> 12:35.950] So I published a quick blog post about that. [12:36.170 --> 12:39.230] And I actually sniffed them out using hypodermic syringes. [12:39.990 --> 12:42.050] So there's some lovely photos that go along with it. [12:42.290 --> 12:44.390] And this hit one of those... [12:44.390 --> 12:45.530] Here's a picture of a cat blogs. [12:46.150 --> 12:47.650] And the electric industry found it. [12:47.730 --> 12:49.030] And it got really, really ticked off. [12:49.790 --> 12:52.210] This is the only thing I've ever gotten hate mail over. [12:52.310 --> 12:53.630] I've gotten lawsuits, mind you. [12:53.630 --> 12:55.830] But this was the only time that I've actually gotten hate mail. [12:56.430 --> 12:58.170] And I started reading through it. [12:58.390 --> 13:06.250] And, you know, it's hate mail, but in that special style of, like, the marketing guy doing hate mail to make it look like his product is not vulnerable. [13:08.810 --> 13:14.210] So when this article came out, they said, oh, well, this is only for the symmetric keys. [13:14.530 --> 13:22.090] And now that we at CertiCom have approved the elliptic curve cryptography, well, if you use our cryptography, then this attack doesn't apply. [13:22.690 --> 13:25.570] So I'm like, okay, how do I break the elliptic curve cryptography? [13:25.970 --> 13:32.650] And so the second exploit that I'm going to show you is on the ChipCon 2430 and 2530. [13:33.010 --> 13:35.670] And it shows you how to extract their elliptic curve keys. [13:38.190 --> 13:41.170] And then they said, well, that requires physical access. [13:41.170 --> 13:44.110] And that doesn't work if you can't touch the device. [13:44.330 --> 13:46.090] And I said, but these are designed to be left exposed. [13:46.110 --> 13:46.950] I can just pick one up. [13:47.130 --> 13:47.950] And they said, argh! [13:47.950 --> 13:48.870] So... [13:50.290 --> 13:51.730] As they do, you know. [13:52.890 --> 14:05.710] So the final exploit that I'm going to show you is on how to exploit the bad random number generators that were used in every library that uses this form of cryptography and actually breaks the cryptography in the process. [14:05.770 --> 14:07.470] So it's possible to remotely extract these keys. [14:10.450 --> 14:14.450] There's also the case of the Freescale MC13224. [14:15.870 --> 14:18.110] This is interesting because it's a much more powerful chip. [14:18.710 --> 14:21.930] Do any of you have the electronic ninja badges from Defcon? [14:22.970 --> 14:26.150] This is what the second electronic ninja badge used. [14:27.310 --> 14:28.990] And I like this chip, too. [14:29.150 --> 14:31.070] But it has some power management issues. [14:31.410 --> 14:35.290] In particular, if you plug the batteries in the wrong way, it just won't boot. [14:36.610 --> 14:41.410] And so I show you how to use that to exploit it and extract all of its keys and firmware and other credentials. [14:44.630 --> 14:46.950] But first, you've got to find it. [14:47.070 --> 14:48.510] Oh, I had a big list that you could read. [14:48.950 --> 14:49.290] Yeah. [14:49.730 --> 14:50.910] I should read my slides more often. [14:52.970 --> 14:54.970] So first I'm going to discuss Zigbee war driving. [14:55.510 --> 14:59.230] Because you need to find these devices before you can actually mess with them. [14:59.230 --> 15:03.770] These radios are usually broadcasting at as little as a single milliwatt. [15:04.130 --> 15:05.750] So the signals don't go very far. [15:07.550 --> 15:09.930] This photograph was taken in Knoxville, Tennessee. [15:13.670 --> 15:14.790] Cheers for the Yeehaw. [15:14.930 --> 15:15.730] I appreciate that. [15:17.410 --> 15:19.910] And, you know, Knoxville is a very neighborly place. [15:20.130 --> 15:20.790] I like it. [15:21.190 --> 15:24.150] I also like... [15:24.150 --> 15:25.450] Well, I don't like how much it rains. [15:25.850 --> 15:27.670] But, you know, you have friendly people. [15:27.670 --> 15:30.730] And one of the advantages is that people drive everywhere. [15:31.070 --> 15:32.030] So, hey, let's go war driving. [15:33.370 --> 15:38.350] The equipment that I used consists of, on the left, a little LEGO box that I made. [15:38.550 --> 15:41.810] I tried to make as many of my exploits LEGO Duplo compliant as possible. [15:43.410 --> 15:45.010] Because I like standards that mean something. [15:48.160 --> 15:50.840] So, you know, I've got this box. [15:50.980 --> 15:51.860] It's got the switch on the top. [15:52.080 --> 15:55.280] The USB plug is for charging it or for reprogramming it. [15:55.280 --> 15:58.540] And then on the right, I have my Nokia N9. [16:01.020 --> 16:04.080] It's like a phone that runs this Linux thing. [16:04.640 --> 16:06.400] But not that fake Java thing. [16:06.920 --> 16:07.200] So... [16:07.860 --> 16:10.360] So, the cool thing is that you can write programs for it. [16:10.480 --> 16:11.560] And you don't have to write them in Java. [16:11.800 --> 16:17.180] So, I wrote a program that connects to the white box and starts packet sniffing. [16:17.180 --> 16:19.340] And also listens for GPS. [16:19.640 --> 16:20.720] Because phones have GPS in them. [16:21.300 --> 16:23.600] And the advantage of that is that you can hop in your car. [16:23.760 --> 16:24.700] And you can start driving around. [16:25.040 --> 16:28.220] And all you have to do is record where you got the packet. [16:28.800 --> 16:29.560] GPS wise. [16:29.920 --> 16:30.860] When you got it. [16:31.180 --> 16:33.080] And you're good to go. [16:33.620 --> 16:36.500] So, this is the hardware in the white box. [16:36.740 --> 16:38.460] Sort of taken out and unfolded. [16:39.480 --> 16:42.580] The little blue board out to the right is the RN42. [16:43.100 --> 16:46.680] It's a really, really easy to use Bluetooth RF-com module. [16:47.100 --> 16:50.000] So that on the device end, I didn't have to write any Bluetooth code. [16:50.760 --> 16:52.340] You've got a battery up top. [16:52.520 --> 16:56.260] And then on the left, you've got the battery charging circuit. [16:56.480 --> 16:57.960] And the power button. [16:58.360 --> 16:59.860] And the power button is just a switch. [17:00.060 --> 17:01.860] And when the switch is in the wrong direction, the power gets cut. [17:02.660 --> 17:08.500] And then the blue board in the middle is a wireless sensor network development kit that was popular in 1997. [17:08.880 --> 17:09.680] Sorry, in 2007. [17:10.460 --> 17:11.760] This is called the TLSB. [17:11.760 --> 17:21.100] If you want to get into Zigbee hacking, while I've not been able to find these on eBay, you can usually find whole hordes of them at universities. [17:21.820 --> 17:36.160] And because the wireless sensor networking bubble collapsed right around 2008, unlike the social networking bubble, which I'm still waiting to pop, these boards are just everywhere and no one is doing research with them. [17:36.240 --> 17:40.020] So if you ask politely, a professor will give you a bunch to play with. [17:40.020 --> 17:41.560] And then you can build all sorts of cool things. [17:43.480 --> 17:47.000] And the tool chain that I use for this is called the GoodFET. [17:47.160 --> 17:50.840] And so I just added Bluetooth support to the GoodFET framework. [17:51.180 --> 17:55.800] And ported the GoodFET firmware to run on the TLSB. [17:56.880 --> 18:01.060] So this is firmware that was originally designed to run on a board that is my own. [18:01.060 --> 18:03.740] And I ported it to work on the commercially available hardware. [18:04.060 --> 18:05.600] And this way I don't have to do any soldering. [18:07.280 --> 18:13.860] And on the command line, all I do is I've got this GoodFET variable that tells which serial port to use. [18:14.120 --> 18:17.620] So in Linux it would be slash dev slash TTY USB whatever. [18:18.260 --> 18:21.720] Here I just set it to the MAC address of the Bluetooth device. [18:21.720 --> 18:27.440] And all of my command line Python scripts that I've written on my workstation also run on my phone. [18:27.980 --> 18:32.140] And this is nifty in case you find something that you recognize and you have an exploit for. [18:32.520 --> 18:36.700] Because you can then run your exploit directly from the phone without having to pull your laptop out. [18:39.060 --> 18:49.560] I also made a Qt Quick app in order to ensure that when I'm fat fingering the phone I can turn the thing on and start it sniffing without having to use the command line. [18:51.960 --> 18:54.140] And the app itself is really easy to use. [18:54.260 --> 18:56.240] You see even the picture is Duplo compliant. [18:57.220 --> 19:02.540] And it just connects to the device, grabs the firmware version, and then starts shuffling packets back and forth. [19:04.460 --> 19:08.200] The end result is exported into Google's keyhole markup language. [19:10.080 --> 19:14.880] You can see here that I'm specifying the packet description and the coordinates as a placemark. [19:15.700 --> 19:18.060] And, you know, I'm sorry, I lied to you. [19:18.140 --> 19:19.800] I said that politics wouldn't be in this lecture. [19:19.840 --> 19:27.040] But I have to point out that Google is discriminating against me by not allowing me to have more than a million records in a Google Maps database. [19:29.500 --> 19:32.380] And, you know, they just had to single me out like that. [19:32.380 --> 19:37.220] I mean, it would be okay if they didn't target just my project. [19:37.700 --> 19:53.200] But if anyone knows how to make a keyhole markup language thing where the items are grouped and ungrouped as you zoom in and out so that I don't hit that million record limit, I would very appreciate knowing this. [19:54.160 --> 19:55.500] And the end result is a map. [19:55.720 --> 19:57.520] This is Cumberland Avenue in Knoxville, Tennessee. [19:58.680 --> 20:04.920] And I have this map just by having my regular GUI application dumped to a text file on disk. [20:05.120 --> 20:06.640] And it just keeps appending to it. [20:08.040 --> 20:11.360] So, as I go around the country, I get records. [20:11.360 --> 20:18.560] So, on my phone now, the Hotel Pennsylvania in Manhattan is already in my records, both from this visit and from prior ones. [20:18.660 --> 20:23.820] And then if I am in Manhattan and I want to see where Zigbee is, well, I can just wander off until I find it. [20:25.460 --> 20:31.940] You'll find Zigbee in the lower floor of the conference, although I haven't yet figured out what it's doing. [20:31.940 --> 20:32.800] It is unencrypted. [20:33.020 --> 20:34.660] And this is unencrypted, too. [20:34.980 --> 20:41.440] And you can tell that it's unencrypted because you see stretches of zeros out to the right, away from the addresses. [20:42.360 --> 20:45.200] In Zigbee packet, the header is very short. [20:46.020 --> 20:49.300] And in an encrypted packet, it is the only thing that is clear text. [20:49.560 --> 20:51.720] And this is how you can very quickly distinguish between the two. [20:55.000 --> 21:00.760] Once you wardrobe around and you actually find something worth attacking, you need to attack it. [21:00.760 --> 21:04.060] And these chips do support security. [21:04.720 --> 21:10.440] It's just that they were not very well secured because they're not trying to do anything important. [21:10.660 --> 21:13.380] They're just trying to get the checklist for the security feature. [21:13.880 --> 21:20.520] So the ChipCon 2420, which was also sold as the Ember 2420, is just a radio. [21:21.100 --> 21:23.080] This chip does not have a CPU in it. [21:23.660 --> 21:28.060] And that's important because it does have an AES-128 engine in it. [21:29.120 --> 21:32.460] So the AES-128 key has to get into the radio somehow. [21:32.740 --> 21:34.940] But the radio has nothing that is Turing complete. [21:35.520 --> 21:40.660] You cannot program the radio in any proper programming language. [21:41.340 --> 21:45.820] It just has a tiny little state machine that knows exactly enough to get a packet in and get a packet out. [21:46.040 --> 21:47.700] And then encrypt it or decrypt it. [21:48.340 --> 21:51.260] And it's doing this through these file-in, file-out buffers. [21:51.260 --> 21:56.920] And all of this traffic goes over the SPI bus, or the serial peripheral interface. [21:58.800 --> 22:01.900] This is a micro-photograph of the chip itself. [22:03.880 --> 22:08.260] And I particularly like this chip because you can actually see the initials of the designers in the corner. [22:09.880 --> 22:15.820] And on my Flickr account, a few of us have been trying to identify who these people are. [22:15.820 --> 22:17.880] And so far only one guy has points. [22:19.500 --> 22:24.880] I'm guessing that he speaks Norwegian, because I can't figure out how else he would be able to Google for these things. [22:26.420 --> 22:31.000] But each one of these initials, and then there's a separate initial thing on the other side of the chip. [22:31.100 --> 22:34.160] Each one of these is one of the engineers who worked on this project. [22:34.760 --> 22:44.760] And in older chips, and in chips which are part of a Skunk Works team, or a new project for a firm, rather than a revision of something old, it's very common to find artwork like this. [22:47.300 --> 22:50.220] Also, if anyone whose name is here wants a free beer, I'm buying. [22:52.600 --> 22:56.620] And this is the same chip that's on the Zalisha Z1 and other development tools. [22:56.620 --> 23:05.180] So it's easy to find these chips and then attack your own hardware before moving on to something that you're worried about breaking. [23:07.400 --> 23:10.040] The SPI bus consists of a chip select line. [23:10.360 --> 23:15.540] This is normally high, and then it drops low to indicate that a message is beginning. [23:16.260 --> 23:19.480] And then you have two data lines and one clock line. [23:19.880 --> 23:22.420] The clock line tells you when to exchange a bit. [23:22.420 --> 23:29.520] And the tricky thing to understand about the data lines is that they are both speaking at the exact same time. [23:31.160 --> 23:32.420] And that this works out. [23:33.680 --> 23:36.560] But the meanings are sort of delayed by a byte. [23:36.680 --> 23:42.580] Because you can't do anything about data that you haven't yet interpreted, and you can't interpret it until it is finished being transmitted. [23:43.000 --> 23:47.460] So usually the first byte from the slave to the master is a status byte. [23:47.460 --> 23:55.080] And that tells the master whether or not, say, a packet is waiting in the queue, or the radio has finished retuning. [23:55.600 --> 23:57.960] And each one of those bits has a single meaning. [23:58.100 --> 24:00.940] So if you mask it off, you can then figure out what state the radio is in. [24:03.120 --> 24:11.600] Because this is a physical chip on a physical board, you can use these lovely things called syringes to stick into the board to actually watch this communication. [24:12.960 --> 24:16.960] This is a picture of a single syringe, just its tip. [24:17.380 --> 24:22.740] And if you look very carefully, you can see the sort of oval that runs around the end of the syringe. [24:23.280 --> 24:27.540] I mean, these circles that I'm hitting, these vias, they're very, very small. [24:28.280 --> 24:33.560] And you need not one, but four syringes at the same time in order to get a clean reading. [24:35.240 --> 24:37.800] So, because you've got to tap every one of these lines. [24:38.080 --> 24:43.240] If you don't get the chip select line, then you can kind of make sense of the bytes, but not by machine. [24:43.360 --> 24:46.920] It requires a human operator to tell when one byte begins and the next ends. [24:48.860 --> 24:51.820] So, the only reliable way to do it involves four syringes. [24:51.820 --> 25:05.880] And you actually have to learn to sit there with your hand in this weird contorted state, holding the tops of all of the needles, while your other hand flips the power switch and then clicks the mouse in order to get the software to read. [25:07.440 --> 25:08.960] This is what the clock looks like. [25:09.160 --> 25:12.100] It idles low and then jumps high for every bit. [25:13.060 --> 25:15.180] And this is what the data lines look like. [25:16.960 --> 25:19.420] Sometimes they idle high, sometimes they idle low. [25:19.420 --> 25:27.480] Sometimes they will idle high but drop low when the chip is selected, which does make it easier to parse if you only have three needles. [25:28.100 --> 25:35.420] And you need to actually have a scope or a logic analyzer and watch these go across to understand what's going on inside of the board. [25:35.680 --> 25:38.220] Otherwise, there's a massive attack surface that you're missing. [25:41.220 --> 25:43.780] And then you can use an application to sniff it. [25:44.280 --> 25:47.300] This is called the Total Phase Beagle Data Center. [25:47.300 --> 25:50.380] They've got good support for Mac, Linux, and Windows. [25:50.840 --> 25:57.620] There's also the Saley Logic Analyzer, which is smaller, more portable, and easier to use. [25:58.400 --> 26:01.600] Unfortunately, the Saley doesn't give you any live recordings. [26:02.180 --> 26:06.260] It only records things and gives you the complete recording after the fact. [26:06.260 --> 26:10.200] So for portability, go with the Saley, or really you should have both in your lab. [26:10.480 --> 26:25.760] But if you're in the lab alone, even though this device is SPI specific, this device just does SPI sniffing, it's sort of advantageous to have a dedicated SPI sniffer in addition to your logic analyzer. [26:29.660 --> 26:37.820] Now, the packet capture that you get here is the set of packets between the host and the radio. [26:38.780 --> 26:42.300] And along that, you'll see commands to retune to different frequencies. [26:43.480 --> 26:44.220] Well, great. [26:44.320 --> 26:45.560] That gives you the channel hopping pattern. [26:45.660 --> 26:50.000] So you then know which frequencies to sniff on with your radio and in which order. [26:50.000 --> 26:53.340] And if you lose your connection to the network, you know which channels to move to. [26:53.800 --> 27:03.280] You'll also see this lovely little handy command that says, write the following 128 bits to AES key zero. [27:05.580 --> 27:07.180] It actually says that. [27:07.380 --> 27:11.900] And the following 128 bits are the symmetric AES key. [27:12.100 --> 27:15.680] And that's all that you need to sniff packets involving that network participant. [27:17.780 --> 27:29.680] To get around this, the more committee-minded areas decided to have a unique key for every single device on the network. [27:30.020 --> 27:35.960] And then let the network coordinator, which is their equivalent of a router, actually switch between the different keys. [27:37.320 --> 27:39.580] If this sounds confusing, it's because it is. [27:39.720 --> 27:40.980] And it causes tons of problems. [27:41.280 --> 27:45.260] And quite often, you'll find one device that just doesn't behave well with this. [27:45.260 --> 27:55.020] So they will either switch back to a single key for everyone, or they will just not bother and leave cryptography off. [27:58.360 --> 28:01.680] The other nifty thing is that they've got to get the key somehow. [28:02.040 --> 28:06.720] And it's either held inside of the device, or it's exchanged over the network. [28:07.200 --> 28:08.960] And public key cryptography is hard. [28:09.360 --> 28:11.740] So as I'll show you later in this lecture, they screw it up. [28:13.860 --> 28:16.520] And it's a lot easier to just shove a key over. [28:17.120 --> 28:20.160] So when Josh Wright was coming out with the... [28:23.620 --> 28:24.100] Killer B. [28:24.320 --> 28:24.820] Killer B. [28:25.060 --> 28:25.260] Yeah. [28:25.340 --> 28:34.560] When Josh Wright was coming out with the Killer B, he actually added this nifty little feature that just sort of listens for the key to come across the network, and then loads that up into the register, and then, hey, it's all clear text. [28:35.540 --> 28:39.780] Because they need to get it in there, and the simplest way is to just broadcast it over the network during association. [28:40.220 --> 28:41.240] And that's what they do. [28:43.460 --> 28:44.560] There are exceptions to this. [28:44.660 --> 28:47.900] I mean, someone somewhere has made a good wireless sensor network. [28:48.080 --> 28:50.100] All I'm saying is that I've never seen one that I couldn't break. [28:52.600 --> 29:00.920] Now, the second revision of this, they recognized that they needed some form of protection, but they didn't add it because they were worried about network protection. [29:01.060 --> 29:05.860] They added it because they were worried about the extraction of firmware. [29:06.980 --> 29:20.600] In the desktop world, if I copy your commercial software directly, well, it has your logo on it, and it has your branding on it, and it's terribly embarrassing, and it's easy for you to know who to sue. [29:21.420 --> 29:27.900] In the embedded world, if I just directly rip off your embedded system, you might never know. [29:29.220 --> 29:33.100] Because there aren't that many people looking at the code or talking to the computer directly. [29:34.760 --> 29:44.980] So embedded system chip manufacturers, when they've got a CPU, they add a lock to it, which is intended to keep neighbors like me from reading your code. [29:46.140 --> 29:53.780] Whether this is to keep me from copying your code or to keep me from figuring out that you copied someone else's code, well, that's none of their business. [29:53.960 --> 29:54.640] They help both sides. [29:57.900 --> 30:02.700] So the ChipCon 2430 and 2530, they support a lock. [30:03.060 --> 30:10.360] And they have no external SPI bus for the radio, because the radio and the CPU are on the same piece of silicon. [30:11.940 --> 30:17.120] And these lock bits prevent you from just politely asking for a copy of the firmware. [30:17.940 --> 30:18.900] Or the key. [30:19.580 --> 30:21.620] So here I'm going to show you how to get the key. [30:21.620 --> 30:26.400] Getting the firmware is more difficult, and we'll get to that in the subsequent chip. [30:26.700 --> 30:29.740] This is a microphotograph of the ChipCon 2530. [30:31.760 --> 30:33.100] And this is the GoodFET. [30:33.240 --> 30:40.220] It's a JTAG debugger that I began, because I was sick of paying $100 apiece for JTAG debuggers when I was a student. [30:41.220 --> 30:45.060] And if you want one of these, you can order a PCB from me. [30:45.360 --> 30:48.440] All of the code, all of the hardware, everything is open source. [30:49.600 --> 30:52.200] And you can just build it, and then debug some chips. [30:52.720 --> 30:57.220] You might have to write your own driver for it, though, because this isn't trying to do all the work for you. [30:57.360 --> 31:01.100] It's just trying to give you a way to touch these chips from Python. [31:02.220 --> 31:07.460] So I wrote an article on how the debugging protocol of these chips works. [31:08.860 --> 31:15.560] These are the waveforms that you produce in order to enter the chip into debugging mode. [31:15.760 --> 31:17.100] So there's a reset line. [31:17.320 --> 31:20.500] And the reset line is high while the chip is running. [31:20.900 --> 31:22.440] So what you do is you drop it low. [31:22.800 --> 31:28.020] And then before raising it, you need to send two clock pulses on the debug clock line. [31:28.360 --> 31:30.200] And if you do that, then the debugger is running. [31:30.680 --> 31:34.040] And two of the pins become different pins. [31:34.180 --> 31:36.940] They become the pins that give you debugging access to the chip. [31:39.920 --> 31:45.440] And the actual protocol is almost the same as SPI, except that you have one data line instead of two. [31:46.540 --> 31:49.200] And the two parties actually take turns writing on it. [31:49.400 --> 31:53.460] You need to be careful that you implement it correctly, or you will both try to speak at the same time. [31:53.460 --> 31:58.680] And while that doesn't break anything, it becomes very difficult to debug. [32:00.560 --> 32:06.340] So after I wrote a driver for this, you could then just plug it into a commercial device. [32:07.080 --> 32:10.340] This is a toy from Mattel called the Girl Tech I Am Me. [32:10.880 --> 32:13.540] It's a text messaging toy for preteen girls. [32:15.560 --> 32:24.680] As you'll see in tomorrow's lecture on P25 by Matt Blaze, Sandy Clark, and myself, we actually have these things reflexively jamming police radios. [32:29.200 --> 32:36.960] This screenshot is not a reflexive jamming, but the device is just consistently jamming at 440 megahertz. [32:39.460 --> 32:43.900] In the foreground, you see my terminal for talking to the I Am Me. [32:44.060 --> 32:45.940] And in the background, you actually see the toy itself. [32:47.420 --> 32:51.100] But there are rules to the locking, right? [32:51.260 --> 32:53.620] And this is great if you want to build something cool out of the toy. [32:53.920 --> 32:55.780] Like what I've shown you so far for this chip. [32:55.980 --> 32:59.240] But it's not enough to actually break a product that uses the chip. [32:59.620 --> 33:02.820] Because you need keys or code. [33:04.540 --> 33:07.480] So we've got our debugger, but our target is locked. [33:07.480 --> 33:12.520] Like every one of these I Am Me's that ships is actually in a locked state as it ships. [33:12.920 --> 33:23.540] And when you connect the debugger to it, you have to erase the toy firmware from it before you can do your own thing with it. [33:24.520 --> 33:30.860] So to unlock it, there's actually a really easy solution they come up with that almost everyone in the industry uses. [33:30.860 --> 33:38.140] And that is that if a chip is locked, you are not allowed to do anything tricky with it until you erase it. [33:38.500 --> 33:41.100] And the act of erasing it also unlocks it. [33:43.640 --> 33:49.760] Their thinking was that if you erase the chip, then there's nothing left for you to steal. [33:50.800 --> 33:52.620] Which is almost correct. [33:53.960 --> 33:57.820] Because when we erase it, we're only erasing flash. [33:58.420 --> 34:00.400] We're only erasing the code. [34:00.760 --> 34:03.260] We're not erasing RAM, which is the data. [34:05.020 --> 34:09.340] So coldboot also works as SRAM if you don't remove power from the victim. [34:09.960 --> 34:13.240] So you can actually just erase all of flash memory. [34:13.740 --> 34:17.840] And then you can copy the data memory out to your hard disk. [34:17.920 --> 34:19.220] And then you have a copy of the data memory. [34:19.840 --> 34:21.340] The SRAM survives. [34:22.680 --> 34:27.220] So the way that the exploit works is that you connect your debugger up to the target. [34:27.860 --> 34:31.260] You verify its model number and its lock state. [34:33.020 --> 34:36.560] And then you unlock the chip by erasing its flash. [34:36.880 --> 34:41.260] And then you copy the SRAM out of it to your disk. [34:41.460 --> 34:43.580] And then you search the SRAM for the network keys. [34:44.000 --> 34:44.920] Or certificates. [34:45.260 --> 34:49.380] And I particularly like certificates because they have headers. [34:49.380 --> 34:51.720] You know, like begin private RSA key here. [34:51.940 --> 34:53.240] Well, thanks. [34:56.730 --> 35:00.290] And the firmware will... [35:00.290 --> 35:05.630] As its beginning, you know, when you're learning C, you learn it on a von Neumann machine. [35:06.040 --> 35:12.380] And in a von Neumann machine, like when you're writing a program for say this laptop, there's no real difference between your code and your data. [35:13.770 --> 35:18.230] And when you run your program, the program gets copied into RAM and it's run from RAM. [35:19.240 --> 35:21.170] This is a Harvard machine. [35:21.570 --> 35:25.020] The code and the data are physically separate. [35:25.380 --> 35:28.670] You use different assembly language instructions to access them. [35:29.050 --> 35:34.670] So when you use a C compiler, you actually have two different types of pointers. [35:34.900 --> 35:38.690] You have pointers to code memory and pointers to data memory. [35:39.440 --> 35:43.110] And the same pointer will mean different things with these different memories. [35:43.330 --> 35:44.590] And they don't always overlap. [35:46.570 --> 35:53.040] So if you do a read from a pointer, as a C programmer, you expect to always get the same word. [35:54.550 --> 36:01.360] But inside of this chip, it depends upon whether you dereference it as a pointer to code memory or a pointer to data memory. [36:02.130 --> 36:04.460] And none of that is passed in a function call. [36:04.830 --> 36:09.900] And no one wants to have to explain this to a beginning C programmer. [36:11.250 --> 36:16.590] So their solution is that in their libraries, they copy all of the keys out of flash memory and into data memory. [36:17.980 --> 36:20.110] So there are actually two places to get a copy of it. [36:22.860 --> 36:26.980] This is a screenshot of the vulnerability test running. [36:26.980 --> 36:33.160] This is just a Z shell script that does these items in sequence. [36:33.380 --> 36:35.000] And it actually pauses and tells you what it's doing. [36:35.440 --> 36:38.050] It first writes something non-random into data memory. [36:39.100 --> 36:42.320] Then it dumps it back out so that it's got a copy that it can look at later. [36:43.400 --> 36:44.920] Then it erases... [36:44.920 --> 36:46.400] Oh, then it locks the chip. [36:46.540 --> 36:50.620] And then it erases the contents of memory by the chip erase instruction. [36:51.760 --> 36:54.620] And then it dumps a second time and then it compares them. [36:54.620 --> 36:56.720] And you can see here that the two are the same. [36:59.200 --> 37:01.780] So you can actually steal certificates and keys this way. [37:02.000 --> 37:03.200] And this is terribly handy. [37:05.050 --> 37:07.280] And lots of chip designers make the same mistake. [37:07.480 --> 37:10.580] Because they thought that only their code memory was worth protecting. [37:10.980 --> 37:12.740] Because that's what their customers are worried about. [37:13.480 --> 37:15.380] If you go back to the Girl Tech IMME... [37:15.380 --> 37:16.520] Jump back a few slides. [37:17.540 --> 37:19.240] So this is the toy on the front, right? [37:19.340 --> 37:23.240] And it's got a big plush logo and the Girl Tech logo on the side and all that stuff. [37:24.000 --> 37:27.040] And it's manufactured in two different factories. [37:28.660 --> 37:30.760] Even though there's no strict need for it. [37:31.160 --> 37:38.540] And the reason why is that toy manufacturers are scared to death that they will go to a major customer. [37:38.740 --> 37:39.580] Let's say Toys R Us. [37:39.860 --> 37:40.940] And say, hey, Toys R Us. [37:41.020 --> 37:45.050] Would you like to buy 200,000 or however many their quantities are? [37:45.440 --> 37:47.400] Would you like to buy a million Girl Tech IMMEs? [37:48.500 --> 37:54.500] Like, their absolute worst nightmare is for the Toys R Us representative to say, I'd love to, but I already bought them. [37:56.200 --> 37:59.640] And that's what can happen when a factory runs what's called a ghost shift. [37:59.820 --> 38:02.700] And they roll extra units off of the line without approval. [38:03.360 --> 38:08.140] But at the same time, you've got to give the factory everything necessary to manufacture your product. [38:08.960 --> 38:20.820] So when they're running this product off, if you look at these pins at the bottom, the ones that I've soldered the wires to, those are actually exposed beneath the battery. [38:21.300 --> 38:25.360] And when you replace batteries in devices, you'll very often see a row of pins. [38:26.240 --> 38:27.700] Those are the debugging connectors. [38:27.700 --> 38:32.640] And that is so that the first factory programs in a test case. [38:33.020 --> 38:42.880] And this test case is never actually sellable to children because no one wants to see the thing boot up and say, test completed. [38:43.260 --> 38:44.740] That would be the worst Christmas ever. [38:47.360 --> 38:59.340] So the first factory produces that, and then a second factory, which has none of the manufacturing files and none of the schematic diagrams and none of the debugging information and none of that. [38:59.480 --> 39:01.520] No electronics manufacturing capability whatsoever. [39:02.360 --> 39:10.780] They have a series of tables in which people are doing nothing but plugging in a programming connector, reflashing the device to make it a toy, and then moving it on. [39:11.240 --> 39:14.900] And if you do that, you can prevent casual midnight runs. [39:15.400 --> 39:21.380] It's still possible to counterfeit your product, of course, but it's harder for your individual factory to do it. [39:24.300 --> 39:30.720] And keep in mind that in embedded systems, that's the sort of attack that these manufacturers are most worried about. [39:31.080 --> 39:44.960] The vast majority of them don't give a damn about my gaining access to these networks because unless it's something both that a criminal could make money off of and something that's very important to stay up, then what's the harm? [39:47.580 --> 39:51.260] So this is the Freescale MC13224. [39:53.020 --> 39:56.260] This board is by a guy named Mariano Alvera. [39:56.460 --> 39:58.000] I'm bad with names. [39:58.360 --> 40:03.740] But he makes these nifty little boards for microcontroller radio development. [40:04.120 --> 40:08.460] On the left, there's an FTDI chip, which implements a debugger. [40:08.460 --> 40:10.760] It's the equivalent of my GoodFET board. [40:11.400 --> 40:16.480] And on the right, there is a Freescale MC13224. [40:17.640 --> 40:23.050] And that is a system-on-package device, which is different from system-on-chip. [40:23.180 --> 40:24.360] And I'll get back to that in a minute. [40:26.280 --> 40:31.540] Now, inside of that device, you have a 32-bit ARM processor, which is great. [40:31.640 --> 40:32.420] You've got tons of power. [40:32.420 --> 40:35.540] And it's got hardware-accelerated cryptography. [40:35.620 --> 40:36.680] And all of that is internal. [40:37.020 --> 40:38.580] And you've got all of these fancy features. [40:38.720 --> 40:40.640] Whatever weird thing you want, this chip might do. [40:41.320 --> 40:43.340] And it's really easy to develop with. [40:43.920 --> 40:45.280] I wish that I could zoom in here. [40:45.540 --> 40:48.000] But no one has made presentation software that's good. [40:54.000 --> 40:55.620] Yeah, not working. [40:58.360 --> 40:59.640] Well, I should... [41:00.590 --> 41:01.440] I should amend that. [41:01.500 --> 41:07.900] No one's made software that's good for presenting that you don't need an App Store account for, even though you've paid for it. [41:07.940 --> 41:15.380] In any case, if I could zoom in on here, you would see that between the chip, the radio chip, and the antenna, there's just one component. [41:17.130 --> 41:19.920] And on almost all of the others, there are tons. [41:19.920 --> 41:22.550] There's a giant analog radio chain. [41:22.960 --> 41:26.740] And it has all sorts of values that have to be carefully calibrated. [41:27.420 --> 41:31.640] And the reason why you don't have to do it here is because Freescale took care of that for you. [41:32.100 --> 41:35.760] And as an electrical engineer, that's really nice. [41:36.020 --> 41:38.140] Because, hey, less work for me to do. [41:40.660 --> 41:42.340] But as usual, there's a problem. [41:44.000 --> 41:52.780] Now, they also go by this method that if the chip is locked, you're not allowed to access it unless you erase it. [41:52.940 --> 41:54.680] But they do it in a slightly different way. [41:55.360 --> 41:59.140] Their way is that the chip begins in a locked state. [42:01.000 --> 42:08.700] And it boots up locked if the first four bytes of whatever it is booting from are L-O-C-K. [42:10.300 --> 42:11.460] Like, as ASCII. [42:11.700 --> 42:13.820] This is a 32-bit ASCII string. [42:16.700 --> 42:17.740] Interesting bug, though. [42:18.720 --> 42:20.980] K-C-O-L does not work here. [42:22.660 --> 42:28.760] Now, the chip boots in an unlocked state if the first four bytes are OK, OK. [42:30.680 --> 42:36.460] It will stop and it will unlock itself if anything else is read from the first four bytes. [42:38.720 --> 42:40.420] Now, this is flash memory. [42:40.640 --> 42:44.900] So when it's erased, it erases to all ones. [42:44.920 --> 42:47.520] So it becomes, like, 32 bits of Fs. [42:49.480 --> 42:55.800] And this way, when the chip is freshly erased, it knows not to try to boot itself. [42:55.800 --> 42:56.800] Almost by accident. [42:59.340 --> 43:01.380] If you take the lid off of the chip... [43:01.380 --> 43:05.140] This is the big square chip with the lid removed using white-fuming nitric acid. [43:07.980 --> 43:09.900] I have lovely things, you know. [43:11.020 --> 43:13.520] But watch out, because this stuff will turn your fingers yellow. [43:13.820 --> 43:14.780] And that's awkward. [43:17.220 --> 43:23.100] So all of these little gold wires that are running off of the chips, those are bonding wires. [43:23.100 --> 43:31.580] And usually, when you take a chip apart, you have those wires running from the chip die in the center out to the legs of the chip, which are on the side. [43:32.540 --> 43:35.620] But in this chip, they run to each other. [43:35.720 --> 43:37.500] They run to little passive components. [43:37.720 --> 43:40.960] These other components are the types of things that you would put under the circuit board. [43:41.240 --> 43:43.180] And that board you see at the bottom? [43:43.360 --> 43:44.280] Well, that's a circuit board. [43:44.280 --> 43:49.780] And what they did was, they just make a small circuit board with three chips on it. [43:50.180 --> 43:54.520] And then they put a bunch of epoxy over it, and that becomes a single package. [43:56.320 --> 43:57.540] This is the main chip. [43:57.800 --> 44:00.400] On the left, you have your ARM7 CPU. [44:00.940 --> 44:02.920] And this is what the software runs on. [44:03.760 --> 44:06.900] On the right, you have the radio regions. [44:07.000 --> 44:09.600] And you can recognize the radio regions because of those... [44:10.100 --> 44:13.260] I call them lollipops, but engineers tell me that they're inductors. [44:14.360 --> 44:15.220] Over on the right. [44:17.540 --> 44:19.780] And these lollipops always indicate the radio. [44:19.980 --> 44:23.560] So if you've got, like, six chips and you wonder which one's the radio, it's always the one with the lollipops. [44:25.020 --> 44:29.740] This one here, with the gunk on top, this is the flash memory chip. [44:30.960 --> 44:33.640] And, again, the gunk on top tells you it's probably a flash memory chip. [44:35.520 --> 44:38.460] And these are the three with all of the other gunk removed. [44:38.460 --> 44:43.480] And you can actually see the fibers of the fiberglass that are sort of woven between each other. [44:45.360 --> 44:48.660] Now, the thing is that this chip here... [44:49.720 --> 44:53.000] This chip here does not have any flash memory. [44:53.820 --> 44:56.920] Or, in fact, any non-volatile memory of any kind. [44:59.600 --> 45:01.320] So, they need to add it. [45:01.460 --> 45:04.620] And they did it by this second chip, which does... [45:05.080 --> 45:06.540] Which actually stores the programming. [45:07.120 --> 45:10.180] Now, this second chip, you can actually read the model number of it. [45:10.300 --> 45:11.840] It's an SPI flash chip. [45:12.020 --> 45:25.800] So, if you had syringes that were, like, careful enough, and they do exist, that you could touch the bonding wires, then you could actually just sniff the program off of the bus as it's copied from the flash memory chip to the CPU during booting. [45:26.240 --> 45:27.820] But then you need a chemistry lab. [45:27.980 --> 45:29.140] You need microprobing needles. [45:29.800 --> 45:34.340] You don't need that much experience with the probe needles as you would to touch inside of a chip. [45:34.400 --> 45:35.060] But you still need a bit. [45:36.040 --> 45:37.940] So, it's not that valuable of an exploit. [45:38.380 --> 45:41.600] And this third chip that I skipped over is just analog stuff for the radio. [45:42.940 --> 45:46.520] Now, this pin here, the one that I've highlighted in red, this pin is lovely. [45:47.760 --> 45:58.640] Because you'll note that almost all of the connections on this PCB diagram run out and away from the chip, and they're on that perimeter. [45:59.300 --> 46:02.620] But there are also some pads on the bottom, and almost none of those are used. [46:03.860 --> 46:08.920] Well, if I jump back to a few frames, you can actually see that those bonding wires actually connect to the PCB. [46:11.250 --> 46:14.120] Those interior pads are test points. [46:15.780 --> 46:19.380] Things that you almost never need to touch, but, you know, every now and then you might. [46:20.400 --> 46:24.860] Perhaps this thing is drawing too much power, and we want to replace the power supply of the flash memory. [46:25.420 --> 46:27.640] Well, this is the pin that you would put that power on. [46:29.840 --> 46:31.640] What happens if I put a short circuit there? [46:33.800 --> 46:38.040] The flash memory gets no power, but the CPU still does. [46:39.220 --> 46:42.920] So the exploit is that you short that pin to ground, and then you boot the chip up. [46:43.340 --> 46:53.800] And the chip is going to crash, because when it tries to read that first word, it does not see OK, OK, and it does not see SCCU, and it doesn't see any of this stuff. [46:55.760 --> 47:05.420] Now, the chip is unlocked as it crashes, because it realizes that it can't boot from flash memory, and it thinks that you need to reprogram it or figure out why it crashed. [47:07.320 --> 47:11.240] So then you remove the short circuit so that flash memory starts working again. [47:11.580 --> 47:14.500] And, of course, it doesn't do anything to inform the CPU of this. [47:15.140 --> 47:18.780] So then you can just hook up a regular JTAG debugger and read a copy of the programming app. [47:19.620 --> 47:20.660] Ram everything else. [47:21.480 --> 47:22.240] Ain't that nifty? [47:29.760 --> 47:38.140] So, I'm running short on time and need to skip the Certicom exploit, but I can tell it in interpretive dance. [47:40.200 --> 47:51.600] There's this company called Certicom, and no one really liked them because they wanted a lot of money for their cryptography standard, which they got written into the Zigbee Smart Energy Profile Standard. [47:52.240 --> 47:59.720] So, but everyone had to deal with them anyways because they held the patent, and they used the patent to enforce licensing of keys. [48:00.500 --> 48:02.720] And they did the licensing through issuing of keys. [48:02.720 --> 48:10.420] So, you had to pay as much to use your own Zigbee library... your own crypto library as you would to use theirs. [48:12.300 --> 48:18.780] And the end result of that was that when they shipped their library, which everyone used, they had a bug. [48:19.100 --> 48:25.740] And the bug was that they didn't explain to the users that you needed a really random number generator. [48:27.080 --> 48:34.160] Instead, they just had a function, and you had to pass this pointer to a function that would return a random 16-bit number. [48:35.460 --> 48:42.440] So, every programmer in every company that used this library said, oh, I've got that, I'll just use the CRAND function. [48:43.520 --> 48:45.540] Because it's the exact same calling convention. [48:47.040 --> 49:01.980] And one vendor in particular, Texas Instruments, they did this lovely thing where they take radio noise and they shuffle it all together, and they come up with a bunch of bytes, and they use those bytes to seed a 16-bit linear feedback shift register. [49:03.040 --> 49:06.880] So, there are only two to the 16th session keys. [49:07.800 --> 49:09.780] You can fit the complete table on a floppy disk. [49:11.720 --> 49:15.140] The other vendors were not so bad, but they were all exploitable in different ways. [49:16.720 --> 49:21.540] So, I would like... I've run out of time, but I would like to invite you to read the f*cking papers. [49:22.940 --> 49:23.900] And I mean that. [49:25.600 --> 49:28.060] There's only so much that you can get in a lecture. [49:28.400 --> 49:34.960] And when you're reading slides, well, you see the pictures, but you don't have the voiceover for them. [49:35.020 --> 49:37.400] And when you watch the video, it's an hour long. [49:37.620 --> 49:42.380] So, I implore you, please go to TravisGoodspeed.com and read my papers. [49:42.500 --> 49:43.680] I did not write them for my health. [49:44.460 --> 49:49.060] And if you go to goodfet.sourceforge.net, you can find a lot of the hardware that I use for these techniques. [49:49.540 --> 49:53.060] And I give away PCBs, either at cost or for free. [49:54.140 --> 49:56.900] And if you want them for free, just send me an address. [49:57.220 --> 49:59.340] Don't send me a question as to whether or not they can be free. [49:59.580 --> 50:02.180] Because that costs me more time, and that's not neighborly. [50:02.720 --> 50:04.900] At this point, I think I have five minutes for questions. [50:05.260 --> 50:08.200] If we could raise the room lighting a bit so that I can see people, that would be great. [50:09.400 --> 50:09.700] All right. [50:10.900 --> 50:11.840] Go up to the mic, please. [50:12.300 --> 50:12.700] Yes. [50:12.940 --> 50:13.460] Run to the mic. [50:14.420 --> 50:16.240] You can push other people out of the way as you're going. [50:17.280 --> 50:18.660] I'm sure the fire marshal would love that. [50:27.670 --> 50:32.270] After an hour of staring at my screen and seeing nothing behind it, I'm now nearsighted. [50:32.610 --> 50:32.970] It's crazy. [50:37.040 --> 50:37.500] All right. [50:37.560 --> 50:37.980] No questions? [50:39.240 --> 50:39.640] Great. [50:39.920 --> 50:40.400] Thank you kindly.