[00:00.640 --> 00:03.360] Hardware Bus Security in Embedded Systems. [00:03.600 --> 00:04.420] Let's welcome Dan. [00:04.680 --> 00:05.040] Thank you. [00:09.430 --> 00:10.090] Thank you. [00:10.750 --> 00:11.430] Well, exciting. [00:11.630 --> 00:14.910] I've often had opposite words used to describe my subject. [00:16.350 --> 00:18.370] But at the same time, I find it very exciting. [00:18.510 --> 00:23.910] And it was one of the topics when I started going through the videos of previous HOPE conferences. [00:24.470 --> 00:26.510] And a lot of them, I really enjoyed them. [00:26.570 --> 00:31.630] And I always felt like there was just a little bit of something missing which happens to be my area of interest. [00:31.630 --> 00:34.650] And that's hacking hardware or how hardware works. [00:34.810 --> 00:43.810] Really, more specifically, I find that hacking in the common sense means figuring out how stuff works, making it work better for you. [00:43.950 --> 00:49.930] I mean, most of the hacks I've ever seen have started off with somebody saying, Man, I really wish this didn't work that way. [00:50.250 --> 00:52.050] And I want to make it work this other way. [00:52.270 --> 00:54.490] And you start taking it apart and figuring it out. [00:54.590 --> 00:55.730] And then you share it with a few people. [00:55.730 --> 00:57.930] And then it becomes a published hack. [00:58.270 --> 01:01.610] And somewhere along the way, sure, some people misuse them here and there. [01:01.630 --> 01:07.010] But generally, it's curiosity or just the desire to make things better. [01:08.030 --> 01:12.790] And so to that end, I wanted to talk about this subject because I rarely ever see much discussion on it. [01:13.230 --> 01:15.390] And yet, for me, I find it equally interesting. [01:15.650 --> 01:18.210] And that's kind of delving into the world of hardware. [01:18.490 --> 01:19.890] And how do you hack hardware? [01:20.010 --> 01:22.030] How do you, you know, what are some of the techniques that are available? [01:22.690 --> 01:26.350] If you're in the mind of security, what can you trust? [01:26.490 --> 01:27.430] And what can't you trust? [01:27.570 --> 01:33.910] What's easily exposed and gotten into as opposed to what's quite difficult and challenging? [01:34.210 --> 01:36.510] You know, so I wanted to talk a little bit about that as well. [01:37.270 --> 01:40.270] I come at this probably from a different angle than a lot of you. [01:40.270 --> 01:43.550] I mean, I program and I write stuff on computers. [01:44.430 --> 01:50.310] And I really enjoy that because I can sit in my own little world and work and really get going on something. [01:50.550 --> 01:54.010] But I always need... I really do need something tangible as well. [01:54.090 --> 02:06.850] And I noticed that the... I think the radio guys and a lot of the other people, there's even people doing art, you know, and making what they do more of an art form instead of just engineering in a practice. [02:07.090 --> 02:15.330] And that's another thing I think I really like about discussing how things work and hacking and all that is because there is, in fact, a certain art to it. [02:15.790 --> 02:18.990] And you can learn a lot about even the design by hacking it. [02:19.070 --> 02:21.910] You can learn about the artist who created the design. [02:22.090 --> 02:23.550] Sometimes I find that quite interesting. [02:24.110 --> 02:27.450] So, well, enough kind of tangential stuff. [02:27.590 --> 02:30.810] Let me answer a couple questions. [02:30.810 --> 02:36.330] I sort of discussed why this topic, but I started to say I came at this from a different angle than most of you. [02:36.390 --> 02:44.530] And that was that I worked in an industry that enabled me to be able to play with hardware, meet a lot of customers who were designing hardware. [02:45.050 --> 02:46.490] I got to travel quite a lot. [02:46.710 --> 02:52.350] I ended up being a manager of engineers in Europe, which is really quite an opportunity. [02:52.650 --> 03:00.650] But at the same time, it exposed me to some constant principles that you see when you're in the many venues that we discuss here. [03:00.730 --> 03:05.090] And that's politics and how things affect what you're trying to do in your little world. [03:05.290 --> 03:13.770] Other people that make laws or try to use these tools as if they're a blunt instrument, when they're really sometimes finely crafted things. [03:13.970 --> 03:15.950] And that's what creates security problems. [03:16.330 --> 03:25.210] You know, you have managers that are trying to save money or cut corners or they don't quite understand what it is that they're using, pushing designers and engineers to get it out and meet the deadline. [03:25.210 --> 03:30.770] And we've got to get this new feature and that new capability so we can market it, you know, so we can sell it. [03:31.410 --> 03:36.650] And what you see is imperfections that creep up into everything. [03:36.650 --> 03:49.250] No matter how good the plan is and the design is, as long as there's a market that you're trying to meet and sales that you're trying to achieve and a manager that... yeah, this guy scares me, by the way, because he looks just like one of my old managers. [03:50.830 --> 03:55.930] And I don't know if it bugs you as much as it bugs me, but maybe it bothers me because he looks just like my manager. [03:56.070 --> 03:58.050] Okay, Jim, you know, I'm trying to get it done here, man. [03:58.170 --> 03:58.470] I'm working. [03:58.830 --> 04:00.210] Just back off a little bit. [04:00.250 --> 04:00.870] I'll get there. [04:02.130 --> 04:08.750] And it's that guy over my shoulder or over other people's shoulder that I saw so often that made me realize, man, there's just a lot of weaknesses out there. [04:08.870 --> 04:17.090] And people think that they can depend on the hardware or that they can depend on the software, you know, to catch the culprit, the terrorists now, or whatever it might be. [04:17.510 --> 04:20.230] But in the end, there's all these underlying faults. [04:20.610 --> 04:33.930] And I feel that one of the things that this group does very well, that sort of hacktivist mentality, is point out what the faults are to wake everybody up that they're there and make sure that we're not so heavily dependent on the things around us. [04:34.210 --> 04:37.370] And trusting people to pass laws is if you can trust these things. [04:38.290 --> 04:42.870] And that by educating people, they're more able to question these things and make decisions for themselves. [04:42.870 --> 04:45.150] So that's the aspect of it that I really liked. [04:45.270 --> 04:47.710] And that's another reason why I wanted to jump into this topic. [04:49.650 --> 05:07.170] And as having come from that perspective and working with literally all the major car manufacturers and game manufacturers, and because the company I worked for and the company before that was involved in microcontrollers and microprocessors and designs in almost every market, [05:07.290 --> 05:08.470] that was certainly their goal. [05:09.090 --> 05:13.010] And so from the inside out, I saw people follow this maxim. [05:13.210 --> 05:26.610] You've heard this before, probably, that Robert Rice, the Secretary of Labor for Bill Clinton said, corporations, in fact, have a legal fiduciary responsibility to maximize their investors' return. [05:28.250 --> 05:35.910] And the reality of that is that what you have is corporations that have boards running them that don't know really anything at all about what they're making. [05:36.810 --> 05:40.970] Their job is to run a public company and make the stock go up and sales go up. [05:41.330 --> 05:46.770] And what they are is a public company who happens to hire some people that make a product to come out. [05:46.770 --> 05:51.710] And so if even the New York Times tomorrow wanted to be something else, you know, they could still do that. [05:52.010 --> 05:53.790] The management could all just decide that. [05:54.130 --> 05:59.310] You know, GE wants to get into bomb making or make blenders or whatever it is that they wanted to be in. [05:59.310 --> 06:03.530] They could do that because the managers of this big public corporation needed to keep growing. [06:03.530 --> 06:05.690] All right, so why all the way down? [06:05.810 --> 06:11.190] Why am I talking politics in a class about bus security and hardware security? [06:11.370 --> 06:21.830] And the reason is politics and fiduciary responsibilities and deadlines and these things are what create all of the security issues that we see. [06:22.010 --> 06:30.050] And almost all of them that I'll touch on here, you can almost always trace back to basically that kind of design mentality and pressure. [06:31.630 --> 06:35.790] We depend in the hardware industry a lot on security through obscurity. [06:36.170 --> 06:40.330] The first layer of obscurity is that not everybody is a hardware designer. [06:41.070 --> 06:44.790] You know, not everybody can take a little board and look at it and tell you what the chips are on there. [06:44.930 --> 06:48.190] And maybe hook up a few probes and say, oh, that's an I squared C bus. [06:48.390 --> 06:51.090] You know, I'll bet that's a memory and that kind of thing. [06:51.170 --> 06:52.810] But you can get that going to community college. [06:53.210 --> 06:59.610] It's not, you don't have to go to aircraft training maintenance school, right, to learn something. [06:59.610 --> 07:03.690] To create a security risk with that product or with any product. [07:04.690 --> 07:07.970] And so obscurity, it's only obscure to the people who don't know. [07:08.990 --> 07:12.530] Which is often the people making our laws and people running our companies and so on. [07:12.770 --> 07:16.490] So I figure if we try to educate on all these levels, that's a good thing. [07:17.870 --> 07:19.030] What's an embedded system? [07:19.170 --> 07:23.330] Well, the easiest way to describe is to start off describing something like it, but that it isn't embedded. [07:23.510 --> 07:25.050] And this is one that you'll know really well. [07:25.050 --> 07:27.910] That's, of course, the computer system and all the stuff connected to it. [07:28.070 --> 07:30.470] I won't belabor the point because it's pretty obvious. [07:30.810 --> 07:36.270] But you have some sort of central processing, which might include high-level math processing. [07:36.270 --> 07:41.830] If it's a video card, it might have really high-level math processing and pipelines, that kind of thing. [07:42.310 --> 07:44.810] There's always some input and there's always some output. [07:44.830 --> 07:48.810] If you don't have any input, for instance, then the thing is working in the dark. [07:48.810 --> 07:50.610] It has no idea what's going on. [07:50.770 --> 07:57.630] So a universal constant with all of these designs is they have some kind of input, which means you can affect the way they behave. [07:58.010 --> 08:00.890] And they all give some sort of output, whatever that might be. [08:00.970 --> 08:01.910] And that's another universal. [08:02.150 --> 08:05.570] If it only accepts input but doesn't do anything, then it doesn't do anything. [08:06.110 --> 08:06.510] Okay? [08:06.590 --> 08:09.570] So it has to have some way of getting that action out. [08:09.830 --> 08:20.210] So everything's got an input and output, and then very often it communicates with things, which is another level above just taking information in, like from a keyboard and putting it out, like on a printer or something. [08:21.270 --> 08:27.490] You're going to load a program, because the world that I'm going to describe here is executional. [08:27.830 --> 08:37.130] There's certainly state machine logic and a lot of other analog designs, and I'm mostly talking about stuff that runs on a computer chip, on a microcontroller, which you'd be surprised. [08:37.350 --> 08:39.950] This microphone probably has a microcontroller in it. [08:39.950 --> 08:44.990] You know, adjusting, compressing the data perhaps, but at least adjusting the levels. [08:45.010 --> 08:48.350] It might be just controlling the pop on and off of the power switch. [08:48.490 --> 08:49.250] It might do almost nothing. [08:49.570 --> 08:59.730] But I wouldn't be at all surprised to open up things all over this room, especially the thermostats and the lighting ballasts and the lights above you. [08:59.850 --> 09:02.890] And in fact, I'll even mention a few more as we move forward. [09:03.330 --> 09:08.450] There's amazing stuff running code in amazingly many places all around you. [09:09.170 --> 09:10.530] And that's what I'm going to talk about. [09:11.350 --> 09:14.950] And then you end up with specialized peripherals, because almost everything does something special. [09:15.210 --> 09:15.550] All right. [09:15.710 --> 09:23.650] And so in the world of design engineer, designing an embedded system, what you're talking about then is trying to get as much of that onto one chip as possible. [09:24.510 --> 09:33.510] And in fact, if you get it all into one chip, and you can get that chip down to as small as possible, then you've really achieved the ultimate prize, which is getting your cost down. [09:34.170 --> 09:39.210] Especially if you can use something that doesn't have to require a lot of engineering and R&D. [09:39.430 --> 09:48.990] And, you know, if you're just buying a library off the market, like MP3 compression or USB bus peripherals, you can get the cost right down. [09:49.150 --> 09:53.070] So you end up with things like standard IO, standard kinds of technology. [09:53.070 --> 09:56.210] And I'll explain why this is important in just a little bit. [09:56.210 --> 09:59.590] So again, you know, coming down, this is still fairly easy stuff. [10:00.270 --> 10:04.710] You've got this programmable microcontroller with a CPU in it. [10:05.270 --> 10:09.430] Everything you would have on a computer in the most boiled down essence of it. [10:09.710 --> 10:17.190] The CPU might have very few really mundane instructions, you know, like some 30 instructions. [10:17.770 --> 10:21.510] A lot of these systems have even fewer instructions than that. [10:21.510 --> 10:23.110] And it might be only 8 bits of data. [10:23.830 --> 10:25.750] So really primitive data types. [10:25.910 --> 10:26.570] No data types. [10:26.650 --> 10:27.430] Everything's 8 bits. [10:27.790 --> 10:30.350] And you have to build from that up, you know. [10:30.530 --> 10:36.510] So you end up with people who are hardware assembler programmers or low-level C programmers, right? [10:36.690 --> 10:40.250] But at some point, really, the thing just becomes another software module to you. [10:40.490 --> 10:41.390] You're writing code. [10:41.390 --> 10:42.250] It does something. [10:42.630 --> 10:44.910] There's a hardware guy that worries about designing it. [10:44.970 --> 10:46.330] That's very often a different person. [10:46.330 --> 10:55.350] And so to the coder of this, it's just another really simple, not too powerful computer that you're programming. [10:55.570 --> 10:56.410] That you're writing code for. [10:58.450 --> 11:03.190] Interesting thing about these things, though, is you're building them into these objects around you. [11:03.490 --> 11:06.470] And you try, as I mentioned, to buy the cheapest product you can. [11:06.590 --> 11:07.870] If you can buy something off the shelf, you do. [11:08.270 --> 11:11.230] And almost everything off the shelf has a communications port on it. [11:11.230 --> 11:16.110] Right off the bat, there's something that pipes data in and out of that chip. [11:16.390 --> 11:16.830] One chip. [11:17.030 --> 11:23.110] Even if you open up an MP3 player and it has one chip in it, there's a good chance that there's a communications port on there. [11:23.310 --> 11:25.390] And it might not even be in use. [11:25.590 --> 11:28.430] You could tap into it and add a piece of hardware to it. [11:28.510 --> 11:30.230] And, in fact, I've got examples of that. [11:31.350 --> 11:38.050] You take that embedded system and then you connect it to a network, you know. [11:38.050 --> 11:45.110] And there was a class earlier on automotive networks where he would have talked about CAN bus and a number of other buses. [11:45.990 --> 11:47.590] But there are so many networks. [11:47.750 --> 11:49.590] And, again, depending on what your need is. [11:49.690 --> 11:52.650] And I'll even give you some examples of what those are here. [11:52.790 --> 11:54.150] But here's a basic system. [11:55.050 --> 11:56.350] You've got an embedded controller. [11:56.550 --> 12:01.090] Some kind of output, which, in this case, is some seven-segment LCDs. [12:01.090 --> 12:02.730] Some sort of numeric keypad. [12:03.150 --> 12:06.990] A little e-square that's electrically erasable memory. [12:07.250 --> 12:10.730] So that it's something that, if you turn the power off, will always be there, but you can change it. [12:12.650 --> 12:15.050] Some sort of a connection to a network. [12:15.830 --> 12:17.190] Or an I/O port. [12:17.590 --> 12:18.830] Some sort of communications port. [12:19.090 --> 12:21.770] And, very often, input from the real world. [12:22.770 --> 12:27.070] In this case, I'm driving a motor with a PWM signal. [12:27.070 --> 12:28.090] A little square signal. [12:28.530 --> 12:31.950] And I'm taking some current readings off of that and feeding it back into the system. [12:32.150 --> 12:36.170] And I show you this because this is almost the universal embedded system. [12:36.990 --> 12:37.430] Alright? [12:37.590 --> 12:38.750] There might not be a motor. [12:38.950 --> 12:40.030] You might be playing music. [12:40.770 --> 12:46.090] But you're still converting something from a digital number that was stored as data somewhere that you wrote. [12:46.290 --> 12:47.450] Perhaps in an e-squared. [12:47.750 --> 12:50.030] And you need to convert that into the real world. [12:50.170 --> 12:51.750] Or it might be a security panel. [12:52.170 --> 12:52.530] Right? [12:52.630 --> 12:53.610] You punch in a number. [12:53.730 --> 12:55.070] And you get a little display. [12:55.070 --> 12:57.850] And if you do it right, there's little beeps that come out. [12:57.930 --> 12:58.910] And the little beeps are sounds. [12:59.030 --> 13:01.630] And those are created by the little PWM there. [13:02.210 --> 13:02.510] Alright? [13:02.830 --> 13:04.070] You might be taking readings. [13:04.270 --> 13:06.290] Maybe you have an RF card reader on that thing. [13:06.530 --> 13:08.250] And so you need an analog input. [13:08.350 --> 13:12.570] The RF card creates a radio wave that gets filtered down to some sort of stream. [13:12.910 --> 13:13.850] You read that in. [13:13.970 --> 13:20.110] So what you see here then, the reason I kind of dwell on this, is it's almost an everything. [13:21.610 --> 13:25.030] Whether or not it's always that keypad or that display. [13:25.750 --> 13:27.210] How much memory it has. [13:27.390 --> 13:28.550] That all changes, of course. [13:28.910 --> 13:29.990] But it's amazing. [13:30.510 --> 13:37.290] Just like I said, this room is filled with things that have this in it right now. [13:40.350 --> 13:46.170] Before I move on actually, let me just give a quick introduction as to why I listed the buses that I did. [13:47.970 --> 13:50.510] I mentioned that you're trying to cut costs, right? [13:50.610 --> 13:51.870] And the boss says, get this out. [13:51.970 --> 13:53.170] We need this to start shipping. [13:53.330 --> 13:55.110] The competitor added this new feature. [13:55.290 --> 13:57.030] The printer can now connect over the Internet. [13:57.970 --> 13:59.710] And we need to add that feature. [13:59.930 --> 14:05.910] And so you go out and you buy a standard processor with this new peripheral on it that you needed. [14:06.350 --> 14:10.570] And you try to port your program that you've always had over into this new thing. [14:10.970 --> 14:12.130] Incorporate this new feature. [14:12.350 --> 14:14.010] It's got a bigger LCD display. [14:14.010 --> 14:15.090] It's got more keys. [14:15.090 --> 14:17.210] It talks over an Ethernet port. [14:17.270 --> 14:19.090] Or maybe it plugs in USB. [14:19.350 --> 14:20.290] You add that functionality. [14:20.510 --> 14:23.450] Do as little as you can to get that functionality added. [14:23.450 --> 14:25.230] Because hours, that's more time. [14:25.370 --> 14:27.370] And engineers to do the work. [14:27.570 --> 14:28.430] And then you ship it. [14:29.050 --> 14:35.510] So what you find is a lot of devices that have been designed with some subset in mind. [14:35.670 --> 14:38.290] And they just keep patching and adding and patching and adding. [14:38.590 --> 14:40.050] Trying to get these new features on. [14:40.250 --> 14:42.270] And you'd be surprised again then. [14:42.490 --> 14:43.790] Actually this group, maybe not. [14:43.990 --> 14:46.730] That if you make it misbehave in a number of ways. [14:47.250 --> 14:50.470] That made sense before, but doesn't make sense anymore. [14:50.470 --> 14:56.370] That you get operation out of the thing that wasn't intended in the latest version of this product. [14:56.570 --> 14:58.870] That's the source of a lot of weird behavior. [14:59.290 --> 15:01.050] And again, I can touch on that. [15:01.170 --> 15:02.070] But these buses then. [15:02.770 --> 15:07.170] What you end up seeing are like SPI and Microwire are two very similar buses. [15:07.330 --> 15:08.310] And I squared C as well. [15:09.050 --> 15:13.130] These serial buses will almost always have a data line toggling up and down. [15:13.230 --> 15:15.550] And a clock line toggling up and down. [15:15.610 --> 15:16.770] So they look very much alike. [15:16.770 --> 15:18.370] You can pick them out almost immediately. [15:19.190 --> 15:21.970] With a scope or with a little box that you might plug into a PC. [15:22.770 --> 15:27.350] And those often write, almost always are what's used in fact exclusively to write to E squared. [15:29.650 --> 15:34.970] And E squared is very important because it could be that you have proximity sensors in a room like this. [15:35.570 --> 15:37.210] For intrusion if there's an alarm. [15:38.110 --> 15:41.370] There are thresholds in that thing that decide whether you're moving or not. [15:43.010 --> 15:46.810] There's smoke detectors in the room to decide what the smoke levels are. [15:47.350 --> 15:51.350] Those have calibration values in them to decide just what is too much smoke. [15:51.690 --> 15:52.970] Or what's not enough. [15:53.210 --> 15:54.610] Light levels for emergency lights. [15:56.710 --> 16:02.050] The air conditioning might have default settings that it goes to if something goes wrong. [16:02.330 --> 16:05.730] Or if it's a holiday and people haven't come to mess with it. [16:05.730 --> 16:08.330] And it might go to some preset condition. [16:08.830 --> 16:12.670] So all of these things end up being, like I said, all around you. [16:12.930 --> 16:16.850] And some of them serve an awfully important function and have no security whatsoever. [16:17.450 --> 16:17.770] Okay. [16:18.130 --> 16:20.750] Except that most of us would not normally know. [16:21.490 --> 16:27.390] It would just be obscure to us that there was no security on that emergency lighting system above the door. [16:29.350 --> 16:31.690] Not necessarily that it doesn't, but it might not. [16:32.190 --> 16:33.530] And you probably doesn't. [16:33.950 --> 16:36.170] So, these buses. [16:36.530 --> 16:37.230] I squared C. [16:37.550 --> 16:40.250] RS-232 almost always for going out to a PC. [16:40.510 --> 16:47.770] And a lot of fairly moderately complex designs to highly complex designs will have a buried RS-232 port. [16:47.990 --> 16:52.270] And the reason is because when I'm developing, I need some way of getting data out of back channel. [16:53.210 --> 16:54.950] So I can monitor how the thing's working. [16:55.330 --> 16:58.630] And I almost always end up doing that through RS-232. [16:58.770 --> 16:59.870] It's the easiest thing to use. [17:00.210 --> 17:02.910] You just connect the wires, you put data in there, and out it comes. [17:03.410 --> 17:04.050] You don't have to know. [17:04.150 --> 17:05.110] No handshaking, really. [17:05.630 --> 17:07.330] It's available, but you almost never use it. [17:07.890 --> 17:09.450] And when I'm done, it works. [17:09.750 --> 17:12.050] And then I tell my boss, okay, I need to clean this up. [17:12.230 --> 17:12.930] No, no, no. [17:13.290 --> 17:14.670] I told you, you're late already. [17:14.810 --> 17:15.610] We've got to get this out. [17:16.150 --> 17:17.390] There'll be no cleaning it up. [17:17.550 --> 17:18.590] Does it work? [17:19.070 --> 17:19.930] Yeah, it works. [17:20.050 --> 17:20.650] Okay, ship it. [17:20.650 --> 17:25.970] You know, that's the hallmark of the product problem and the bugs that we all find. [17:27.370 --> 17:32.110] So, almost always, there's some embedded RS-232 port in these moderately complex designs. [17:32.390 --> 17:35.470] Can, if it's in an automobile or if it's out in a production environment. [17:36.130 --> 17:37.770] Dolly, they're starting to do... [17:37.770 --> 17:40.190] This is a digitally addressable lighting interface. [17:40.550 --> 17:46.710] So that ballasts in hotels, for instance, is a good example, can be controlled electronically. [17:46.710 --> 17:49.950] So, let's say this room, the room over there, the A room, can be divided. [17:50.550 --> 17:53.670] And so, maybe you want the lights to control different sections of the room. [17:54.110 --> 17:56.390] So, they have a bus running around to the ballast. [17:56.490 --> 17:59.070] And they say, alright, you're learned over to this switch. [17:59.470 --> 18:02.210] You think this switch actually switches power, but it doesn't. [18:02.570 --> 18:08.010] It sends data on a bus that says, alright, everybody who's been learned to me, turn off. [18:08.910 --> 18:09.350] Okay? [18:10.090 --> 18:16.110] And these, you know, 16 ballasts know that they've been addressed and they'll turn off. [18:16.270 --> 18:17.450] Or they'll dim or whatever. [18:17.790 --> 18:21.950] And then, if I need to reconfigure the room, I open this little hatch on the side of the room. [18:21.950 --> 18:25.670] And I get in, and I say, alright, I want to learn this quarter over to here. [18:25.790 --> 18:27.990] Maybe somebody's already pre-programmed all these things. [18:28.150 --> 18:29.830] And I just select these pre-programs. [18:29.990 --> 18:31.910] There's another bus, right? [18:31.910 --> 18:34.830] Some really important functions, lights, in a hotel. [18:36.170 --> 18:36.970] And programmability. [18:37.190 --> 18:38.930] And they all look like this, you know. [18:39.090 --> 18:40.250] And they're using standard buses. [18:40.250 --> 18:42.010] And they're right there behind a pack panel. [18:42.190 --> 18:44.970] And on an old hotel like this is a classic example. [18:45.090 --> 18:57.450] Old hotels, old hospitals, buildings where, anywhere in the northeast, where these old buildings didn't have really good power and lighting conduits run in the walls. [18:57.470 --> 18:59.710] And easy access to junctions and all that. [18:59.770 --> 19:01.530] And so you see this stuff right on the wall. [19:01.890 --> 19:04.190] On the outside of the wall, they'll just drill a hole through the wall. [19:04.190 --> 19:05.330] And up goes the cable, right? [19:05.450 --> 19:06.090] You see it everywhere. [19:07.150 --> 19:08.810] Junction boxes that are left open. [19:08.950 --> 19:13.370] Closets that have been converted over to patch networks and things like that. [19:13.770 --> 19:19.670] And so, kind of what I'm falling back to here is, there's ways to prevent all of this. [19:20.470 --> 19:22.370] These are the exploits that are available. [19:22.550 --> 19:25.190] And we'll go into a more deeper analysis of this. [19:25.190 --> 19:27.830] But almost a little bit, so what, you know? [19:29.070 --> 19:32.230] On the other hand, you have to practice a better... [19:32.230 --> 19:37.290] I mean, you buy these interfaces, and then you let the wires be run outside the building, and where's your weakest point been put? [19:37.550 --> 19:39.110] And you just hope nobody notices. [19:40.490 --> 19:43.810] But you hope also that you take good care of your employees, you know? [19:43.810 --> 19:49.070] And that no disgruntled employees leave the company knowing this stuff and passing along, you know? [19:49.830 --> 19:56.090] That's one of my top pieces of advice, if you want to secure your building, is take good care of your employees, you know? [19:56.630 --> 19:58.190] And things tend to go a lot better. [20:00.450 --> 20:04.250] So we talked about an embedded system, and what's typically in an embedded system. [20:04.510 --> 20:11.270] And I'm going to give some... these are probably obvious examples of embedded systems, and things that get networked. [20:11.810 --> 20:13.830] I've talked about lighting ballasts. [20:13.910 --> 20:14.650] I don't show one here. [20:14.870 --> 20:17.150] There is a smoke detector. [20:17.450 --> 20:19.510] It's very common for these to be networked now. [20:19.930 --> 20:21.630] And I'll give you some obvious reasons. [20:21.630 --> 20:31.810] If you have a fire, and it's a building like this, and there's nobody around to see it, there's still a fire, despite the little joke about the bear being in the woods, right? [20:32.270 --> 20:34.230] Or if a tree falls in the woods, does he make a noise? [20:34.910 --> 20:36.050] Yeah, there's still a fire. [20:36.170 --> 20:37.250] There's nobody there to see it. [20:37.570 --> 20:42.270] It sets off some monitors somewhere, and perhaps a security guard goes and checks it out. [20:42.670 --> 20:44.670] But it's got to set off a monitor somewhere. [20:44.870 --> 20:46.430] It's got to set off an alarm somewhere. [20:46.910 --> 20:50.270] Maybe it's even going to trigger something to decide whether to call the fire department. [20:51.210 --> 20:57.650] So, in a big building like this, in a lot of buildings, again, where you really need better security than that, you've got these standard buses. [20:58.530 --> 21:02.270] One of those buses that I pointed at before is probably what's going to connect this thing. [21:03.710 --> 21:04.930] Wires that are right out in the open. [21:06.130 --> 21:10.810] Even if you were to, you can buy the thing on the market and take it home and hack it. [21:11.050 --> 21:15.210] So, it's not like you have to sit here, you know, with wires up to the ceiling. [21:15.370 --> 21:20.790] What the hell is that guy doing up on the ladder, you know, pulling the fire detector apart? [21:20.790 --> 21:24.490] You can buy one and take it home and tear it apart and figure it out. [21:25.550 --> 21:30.470] And so, and then, again, very often exploits are learned that way, the hard way. [21:30.790 --> 21:36.010] And then you find out that, oh, lo and behold, there was this easy thing that if you just held the button for too long, it would go off. [21:36.430 --> 21:36.890] You know? [21:37.190 --> 21:42.470] And you might not ever have tried that, because it makes a heck of a lot of noise first, right? [21:42.470 --> 21:43.950] And draws a lot of attention. [21:44.530 --> 21:54.710] But if you knew that the speaker was built too close to the grill, and all you had to do was hold a wet paper towel to it and then hold the button too long, that it didn't make much more than a squeak, and now it's off. [21:55.210 --> 21:55.570] Right? [21:55.730 --> 22:00.810] And now you've learned something about the thing that you bought on the open market that has created a security breach. [22:01.090 --> 22:02.490] So, again, what's the lesson learned? [22:02.610 --> 22:07.710] Well, don't depend too heavily on things that are, that ultimately, somewhere along the way, they're going to get broken. [22:08.470 --> 22:11.150] And most of the examples I give you are unfortunately true. [22:11.550 --> 22:14.670] So, therefore, I won't name the company that had it. [22:15.690 --> 22:17.810] These proximity detectors are the same thing. [22:18.010 --> 22:23.730] That's the one just to the right of the smoke detector, where it detects the changes in infrared levels. [22:24.690 --> 22:28.570] And some of them have microprocessors in them that are actually fairly sophisticated now. [22:28.650 --> 22:32.530] They try to, you know, not turn on for a cat or a plant that's fallen over. [22:33.490 --> 22:40.970] Something that some intelligence could have said that you shouldn't have a false alarm, because what if you have too many false alarms? [22:41.230 --> 22:43.310] Then the fire department or the police department doesn't want to come anymore. [22:43.850 --> 22:52.770] So you have to have some intelligence that says don't call the police over stupid stuff, or my insurance goes up and my security costs go up. [22:52.830 --> 22:53.810] And then who starts complaining? [22:54.670 --> 23:01.170] You know, the manager of the building is complaining to the facilities guys that your damn alarm system turns on too easily. [23:01.350 --> 23:03.150] And so what's the facilities guy going to do? [23:03.150 --> 23:04.570] He's going to turn it down. [23:05.050 --> 23:07.430] Or he's going to make sure that he doesn't have any false alarms. [23:08.150 --> 23:14.170] If he's disgruntled, he might just complain enough to other people to recognize that there are weaknesses in the system. [23:15.810 --> 23:27.290] Another classic example is security that's too tight, where, for instance, I've worked in some buildings that had some really intense security, which, you know, you've got to show up, you've got to go by a guard, and you've got to have your bag inspected, [23:27.310 --> 23:31.990] and you've got to show a badge, and you've got to go through a reader, and then you've got to have a key to get past a certain door. [23:33.270 --> 23:36.710] But there's so much security that people prop the doors open, you know. [23:37.290 --> 23:46.730] Or they cover up cameras because their girlfriend's coming to visit at lunch or whatever, you know, and they don't get paid enough guarding this place to just sit here and be bored all day. [23:46.890 --> 23:48.370] So they learn the tricks. [23:49.110 --> 23:54.590] So again, sort of over-intense application of security creates problems too. [23:54.790 --> 23:57.530] It's one of these quandaries of developing a good system. [23:57.530 --> 23:59.030] So other embedded networks. [23:59.930 --> 24:06.190] The card reader, which is on the bottom left on this picture, maybe a little RF card reader has got a bus connected to it. [24:06.250 --> 24:07.790] It's probably got e-squared on there. [24:08.570 --> 24:12.030] There's all kinds of stuff going on there that's pretty important. [24:12.690 --> 24:16.070] And again, it's pretty standard stuff, easy to get a hold of. [24:16.190 --> 24:17.250] And what's in there? [24:17.330 --> 24:18.310] There's a program in there. [24:18.390 --> 24:20.530] Well, if you could get the program, you know exactly how it works. [24:21.030 --> 24:30.110] If you could compromise it, you could have a special number or a special card that you brought to it that it just says, play the last number, you know, back in. [24:30.230 --> 24:32.070] So somebody got in with a number, right? [24:33.370 --> 24:39.550] And you've told it when I key in this number, play the last number, whatever was good. [24:39.730 --> 24:43.010] And then that gets sent up the bus to the system that says, yeah, okay, go ahead and lock the door. [24:43.010 --> 24:50.270] So you can do this compromise of the system and come back months later and actually activate it. [24:50.470 --> 25:00.930] And even if they have video cameras or something like that, are they going to go through 24, seven hours of video for months trying to find when that happened? [25:01.050 --> 25:03.710] They're probably not even going to question that something's wrong with the panel to begin with. [25:03.710 --> 25:14.070] And if they do open it, unless they've been smart about tamper-proofing it and preventing that kind of access, they're probably not going to catch it, you know. [25:14.190 --> 25:18.450] And we talk about lock picking in one of the other panels, and that's exactly the same thing, right? [25:18.470 --> 25:19.830] You can buy the lock and take it home. [25:20.810 --> 25:26.870] Now, once you really know how it works, you can go in and do your little mojo in moments and do what you need to do. [25:26.950 --> 25:30.550] And that's why, again, you have to be really careful on the security you depend upon. [25:30.550 --> 25:32.530] And what about who's watching you? [25:32.610 --> 25:34.230] I love the shirt, Watch the Watchers. [25:34.890 --> 25:37.630] Because how many of these cameras do you think are on buses now? [25:38.290 --> 25:40.610] They're transmitting or they're on some kind of a bus. [25:40.790 --> 25:47.810] And a lot of these hardware buses have some sort of black box receiver that's only, you know, only in this room with this locked door. [25:48.070 --> 25:51.370] But it's a standard thing that you can buy and pull the cover off. [25:51.390 --> 25:53.690] And if you probe it, you'll find there's standard buses in there. [25:54.590 --> 25:59.130] And everything that you need to know, probably an extra RS-232 port thrown in. [25:59.130 --> 26:04.290] And with a little bit of inside knowledge, you've got access to the system. [26:04.450 --> 26:06.870] Without some inside knowledge, you probably have your work cut out for you. [26:07.030 --> 26:09.710] And there's still a lot that can be done, which I'm going to talk about. [26:11.370 --> 26:22.090] So everything from the dumbest little smoke detector, which just has a little chamber that it tries to detect smoke in, all the way up to fully computerized security systems, rack mount systems. [26:22.450 --> 26:25.030] All of these things have all these standard buses inside of them. [26:27.090 --> 26:30.030] Here's a perfect example of this, then. [26:30.430 --> 26:32.350] I went right for a security example. [26:32.450 --> 26:42.230] Because even though I said manufacturing systems, all kinds of systems are bust, security is where you get people's attention if you want to talk about something. [26:42.230 --> 26:43.150] But it's all the same. [26:44.350 --> 26:49.990] So don't let this model fool you into thinking this is the only place where the breach is. [26:50.150 --> 26:52.710] But here you have a person, and they're sitting at a desk. [26:52.910 --> 26:54.170] They've got a USB reader. [26:54.830 --> 26:56.150] You know, they're making a badge. [26:56.390 --> 26:58.070] We'll start from the point of making the badge. [26:58.110 --> 26:58.970] You've got a USB reader. [27:00.230 --> 27:01.770] And I've got these blanks. [27:01.810 --> 27:05.430] And I'm going to learn the blank to the reader and say, right, I'm getting ready to add Joe Smith. [27:06.470 --> 27:13.510] Then I've got a camera system where I probably connect it to a computer where I enter, go ahead and take the picture, marry it up to this number. [27:13.590 --> 27:14.390] I'm going to scan now. [27:15.170 --> 27:16.370] And make a badge. [27:16.870 --> 27:18.570] And I make the little badge and I give it to you. [27:18.650 --> 27:21.290] Welcome to the company, new employee orientations down the hall. [27:21.550 --> 27:24.630] And I'm sorry that nobody warned you about coming to work here. [27:25.070 --> 27:25.730] I'm sorry. [27:26.070 --> 27:27.230] Bitter days coming back again. [27:27.450 --> 27:27.830] Flashback. [27:28.130 --> 27:32.290] So, but that's on some kind of a network. [27:32.290 --> 27:36.290] And something else has to access that table of legitimate users. [27:37.150 --> 27:39.990] And so there's somewhere, some table of users, right? [27:40.050 --> 27:45.690] And when you go in and wave your badge or punch in your number or whatever to this super secure area, it's got to go and look up this table. [27:45.950 --> 27:51.590] And so this group knows really well that one of the most obvious places of compromise is get a number in there. [27:51.890 --> 27:53.150] Find out what the badge is. [27:53.310 --> 27:55.350] Make one with a number and get your number in there. [27:55.710 --> 27:56.590] And now you're in. [27:56.670 --> 27:57.250] Easiest can be. [27:57.330 --> 27:58.590] You don't even need to know how to pick a lock. [27:58.810 --> 27:59.970] I mean, you hardly need to know anything. [28:00.470 --> 28:13.670] And so is that security that you want to depend upon to protect, you know, very chemicals or laser systems or a lot of the stuff that's in hospitals or something like that? [28:13.730 --> 28:16.370] Well, that is what's protecting most of those places, you know. [28:16.530 --> 28:22.910] And not to make people paranoid, but the point is to make people paranoid enough to know that you just don't depend on that stuff entirely. [28:23.310 --> 28:30.350] If you're staying in a hospital, a lot of people still put an arrow where the surgery should be, you know, so they don't get the wrong foot worked on. [28:31.110 --> 28:34.010] And you should know who your doctor is and he should know his equipment. [28:34.330 --> 28:37.650] And, you know, there shouldn't be any last-minute surprises and that kind of thing. [28:37.870 --> 28:46.330] Or in a building access, funny people tampering with the panels and things like that are to be observed and questioned. [28:46.330 --> 28:51.950] But you have a panel, you have a network to a patch panel where multiple panels might come together. [28:52.110 --> 28:55.130] You have a solenoid in the door which is being told to open. [28:55.370 --> 29:01.170] And very often in these security systems you have like a panel, an access panel, that controls the door solenoid. [29:01.730 --> 29:06.690] And then what it sends is a signal that says, hey, can I open the... he just entered this. [29:07.550 --> 29:11.230] I don't know, this was entered on my panel or this is the card that was waved in front of me. [29:11.310 --> 29:12.250] Can I unlock the door? [29:12.650 --> 29:13.950] It sends off a signal. [29:14.230 --> 29:17.170] And then back comes the response that says, yeah, go ahead and unlock the door. [29:17.450 --> 29:18.670] Well, how dumb is that? [29:18.850 --> 29:23.070] Because the door lock is right there, local to the panel. [29:23.270 --> 29:27.350] And so if you can get at the panel and you know how it works, you can just tell the panel to open the door. [29:27.510 --> 29:30.350] You don't even need permission from the network. [29:30.350 --> 29:35.810] And so there's a number of security breaches that are based precisely on that model. [29:36.290 --> 29:37.230] And how do you find them? [29:37.290 --> 29:40.410] Well, you buy one of these panels or you get one as a sample. [29:40.550 --> 29:43.930] You call them up and you say, I'm doing a design and I need this panel. [29:44.750 --> 29:48.770] You know, we're security ink and we're going to make hundreds of thousands of these things. [29:49.810 --> 29:51.730] And that's a legitimate way of doing design. [29:51.870 --> 29:58.970] And so they send you these things and people all the time get them and have them in their hands and tear them apart. [29:59.670 --> 30:04.490] And again, you know, as a manufacturer of this stuff, you don't really want to curtail that because you want people to use your products. [30:05.190 --> 30:07.410] But you just depend upon people using them wisely. [30:09.310 --> 30:14.050] So I came back to this just to remind you then that that system was just an extension of this. [30:14.050 --> 30:20.730] And so that all over that network were all kinds of things that had little local buses in them that could all be compromised. [30:21.890 --> 30:25.030] And their behavior modeled and understood. [30:26.470 --> 30:35.170] All the way up to this one, I just, by way of example, pulled it off the Internet, not to suggest that they have any security problems. [30:35.190 --> 30:35.770] I hope they don't. [30:35.790 --> 30:39.390] It's the International Fusion Materials Irradiation Facility. [30:41.270 --> 30:48.250] And again, just not to point out that they have flaws, but just pointing out that they have a LAN and they have all these local buses. [30:48.250 --> 30:51.590] And for some reason, they published a model of their security on the Internet. [30:52.630 --> 30:53.030] And... [30:54.870 --> 30:56.510] But it's not a very detailed one. [30:56.630 --> 30:57.570] But it is. [30:57.870 --> 31:01.430] Because you didn't even need this just to know that this was what was going to be there anyway. [31:01.810 --> 31:05.770] There's going to be some sensors to say that the radiation level is below what it needs to be. [31:05.850 --> 31:06.930] Or is the laser too hot? [31:07.290 --> 31:09.630] Or does somebody have access that shouldn't? [31:09.730 --> 31:11.610] Is the safety shielding not down? [31:12.690 --> 31:14.750] You know, are there contaminants in the room? [31:14.890 --> 31:18.730] We're going to run a super hot laser and there's contaminants in the room and they're going to super heat. [31:18.930 --> 31:24.190] And we're going to have a little explosion if we don't have, you know, Johnny just not supposed to smoke in here. [31:24.370 --> 31:25.650] You know, or whatever. [31:25.850 --> 31:32.290] So all the little sensors that detect these qualities, then they have to make decisions. [31:32.490 --> 31:34.870] And some of those decisions pertain to security. [31:34.910 --> 31:44.370] And the point I wanted to make here is that you begin to see where a model of having the smoke detector and the air conditioning and the access panel and all that you could justify. [31:44.390 --> 31:48.490] You could begin to think of reasons why you could justify hooking them all together on one network. [31:48.950 --> 31:52.330] You know, because to the designer, to the pure designer, that makes perfect sense. [31:52.750 --> 31:55.410] You know, the smoke detector can tell me what the air quality is. [31:55.410 --> 31:58.730] And I can know if someone's come in and out by the security system. [31:59.090 --> 32:02.730] And all of that, and if the shielding is down, then there's a little button that gets pressed. [32:02.730 --> 32:11.770] And you're going to trust all this data that you've got over standard protocol buses using, you know, out of the specification means. [32:12.030 --> 32:16.110] And then you're going to make a decision to turn this super powerful piece of equipment. [32:16.170 --> 32:17.090] Maybe it's a milling machine. [32:17.270 --> 32:17.990] Maybe it's a laser. [32:18.410 --> 32:21.230] You know, maybe it's an airplane or something. [32:21.450 --> 32:25.030] But the point is that you can't trust all of that. [32:25.270 --> 32:28.490] Somebody still needs to be able to look around and know that you're not supposed to smoke in here. [32:28.490 --> 32:31.850] And that that guy shouldn't be in there, you know, before we turn this thing on. [32:32.430 --> 32:38.110] But it's when you start to cut costs and you begin to cut corners because everything's going well and we've never had a problem before. [32:38.470 --> 32:40.870] I've never heard of that happening, you know. [32:41.210 --> 32:43.550] And, no, everybody here, we trust all of them. [32:43.550 --> 32:44.790] We never change our passwords. [32:45.910 --> 32:50.770] The little IS guy, because there's such a bureaucratic nightmare to change a password, you know. [32:51.030 --> 32:56.310] Sometimes these levels of administration even thwart your best security attempts. [32:56.970 --> 33:06.250] So the point is, there's standard stuff all over and even the systems that are intended to be the most secure are going to have weaknesses that exist like this. [33:07.610 --> 33:12.730] But the day is coming and is here already, in fact, where you're not going to stop progress. [33:14.250 --> 33:16.790] Networking things together is a really good thing in a lot of ways. [33:17.230 --> 33:20.330] Things work more smoothly, much more invisibly. [33:20.330 --> 33:23.910] You know, they make these washers and dryers now. [33:24.330 --> 33:29.310] Where, you know, you put a load in the wash and the washing machine has to have a few more sensors. [33:29.310 --> 33:31.130] How dirty are the clothes? [33:31.330 --> 33:32.290] Are they colors? [33:32.610 --> 33:34.290] What kind of fabric do they appear to be? [33:34.450 --> 33:40.690] They are able to basically do kind of a spectrum analysis of the contents as the sensors keep getting cheaper. [33:40.690 --> 33:45.090] And why not pass that information over to the dryer so that the dryer works a little bit better. [33:45.230 --> 33:48.750] And if you pass that information over to the dryer, then the dryer doesn't need those sensors. [33:48.910 --> 33:50.650] So it makes perfect sense that they be networked. [33:50.970 --> 33:54.150] And you think, well, why would I want a washer and dryer of this network? [33:54.470 --> 33:58.150] But then, you know, I've got all these buttons and cables and stuff because you don't see that. [33:58.350 --> 34:01.230] What you'll see is a lid and a button, you know. [34:01.450 --> 34:04.550] You open the lid and stick your clothes in and close it and push a button. [34:04.550 --> 34:05.890] And man, this thing always works. [34:06.350 --> 34:10.030] And then I take it and I put it in the dryer and I push a button and it always works, you know. [34:10.190 --> 34:18.430] And these things become possible because more data and more sensitive sensors and better communications and all that. [34:18.510 --> 34:23.830] But they also, of course, open up funny things like your neighbor just might know more about your washer and dryer than you do. [34:26.070 --> 34:32.570] And if they're connecting over an RF link, because who knows where they're going to be in relationship to each other. [34:32.570 --> 34:34.410] And we want to make it as easy as possible. [34:34.670 --> 34:38.850] So I know we'll have these things communicate via RF, which is real. [34:39.270 --> 34:40.430] And these products exist. [34:40.610 --> 34:43.270] And then we won't have to worry about that quite so much. [34:43.470 --> 34:46.550] And now, of course, now you've created a really hackable, weird environment. [34:47.690 --> 34:52.190] But carry that forward into manufacturing or, like I said, security or medical or anything. [34:52.370 --> 34:56.190] And you begin to see where the possibilities towards problems exist. [34:56.370 --> 34:59.170] Even beyond hacking, just failure, you know, of one kind or another. [34:59.170 --> 35:06.030] So PBXes, your phone, I'm sure you well know this, is not going to be a phone anymore. [35:06.390 --> 35:07.690] It's a terminal device. [35:07.990 --> 35:13.030] I mean, the moment you're doing voice over IP, maybe you're even encrypting the data. [35:13.310 --> 35:22.530] But ultimately, there is this highly functional embedded system in your hand or on your desk or in your pocket or wherever it might be with all the same stuff going on it. [35:22.530 --> 35:30.970] And you can buy it on the open market and you can bring it home and tear it apart and figure out how it works and figure out what kind of things can be done to compromise it. [35:31.070 --> 35:32.530] And can it be made to spy on you? [35:32.650 --> 35:41.910] Or can it be made to fail when you want it to work through denial of service attacks or, you know, the usual mechanisms on the network side? [35:42.290 --> 35:44.810] Or through some compromised security on the hardware side? [35:44.930 --> 35:47.750] Somebody just gets a hold of, figures out what kind of phone you have. [35:48.370 --> 35:53.110] And somebody wants to bug the boss and brings in a different phone when he's not looking. [35:53.670 --> 35:59.590] And next thing you know, you've got a microphone on your desk that behaves just exactly like your phone did. [35:59.590 --> 36:05.810] And that's, I'm sure you realize by reading the paper, there's a lot of bad people out there. [36:07.230 --> 36:08.710] Somebody voted for some of them. [36:10.950 --> 36:16.770] And this stuff is possible and it becomes more possible as technology increases. [36:17.110 --> 36:21.150] GPS is in your cell phone telling emergency where you are. [36:21.250 --> 36:21.890] That's a good thing. [36:21.890 --> 36:31.930] You know, if I get hit by a car and the guy drives off and I'm in the nowhere, I'll probably be glad that my phone, you know, narked on me and told everybody where I was. [36:32.550 --> 36:41.510] But at the same time, if I happen to come to a hacker conference and present on a topic that maybe people don't like, I wouldn't really want people to think that was something wrong. [36:41.730 --> 36:46.870] And I'm not saying that that would happen, but that's the kind of environment that starts to get created when people don't understand. [36:46.870 --> 36:51.890] That this is just common knowledge in some circles, like the designers of this stuff and not in others. [36:52.830 --> 36:57.670] And so again, kind of beating the drum of what the message is about, which is educating people. [36:58.810 --> 37:08.970] Building maintenance, building management, I talked about security and fire systems and building access and ventilation systems. [37:09.210 --> 37:13.870] And when you have a large building like that or like this, you have water systems, right? [37:13.870 --> 37:19.790] You have building-wide sensor networks that have to be able to manage what the... [37:19.790 --> 37:21.590] I mean, how much hot water do you need? [37:21.770 --> 37:26.570] And is the laundry being cranked up for such a big facility as this? [37:26.670 --> 37:27.970] Is there steam that needs to be vented? [37:28.090 --> 37:28.790] Whatever, you know. [37:29.070 --> 37:32.610] Which way do the HVAC doors need to route the hot air? [37:32.710 --> 37:34.450] Maybe we're trying to conserve some of it. [37:34.530 --> 37:35.930] Maybe we're trying to vent it to the outside. [37:35.930 --> 37:43.790] So these air circulation and all kinds of things get controlled from these central systems. [37:44.070 --> 37:46.410] And you don't necessarily have to hack the central system. [37:46.690 --> 37:50.670] These things are so dependent on data coming to them. [37:51.030 --> 37:53.250] And so often the decisions they make are absolute. [37:53.670 --> 37:57.130] If the sensor says this, then I turn on the fan. [37:57.310 --> 37:59.770] And if it says that, then I turn off the fan or I turn it down. [37:59.770 --> 38:07.730] And so you don't necessarily always have to hack the computer that's at the security desk in order to be able to cause problems. [38:09.330 --> 38:10.890] Manufacturing floor hospitals, I mentioned. [38:11.250 --> 38:12.530] Mining and industrial. [38:13.290 --> 38:14.890] You know, train systems. [38:15.870 --> 38:19.030] Everything you can think of that has to have a certain amount of control. [38:19.490 --> 38:24.090] You think of a train and you think, oh, there's only a computer running the train. [38:24.090 --> 38:24.610] But there's not. [38:25.090 --> 38:28.330] There's a little microcontroller controlling the motors of the door. [38:28.570 --> 38:33.010] And then they maybe read the back EMF that gets created if somebody's in the door. [38:33.130 --> 38:34.290] And then reverses the door out. [38:34.530 --> 38:37.510] And there was a threshold that determined whether or not there was somebody there. [38:37.730 --> 38:39.410] And somebody had to program that in. [38:39.510 --> 38:40.590] Well, imagine that getting trained. [38:40.810 --> 38:42.630] You know, or changed or something like that. [38:44.490 --> 38:46.570] So again, you have to have emergency exits. [38:46.710 --> 38:49.250] You have to have a way that a person is allowed to open a door. [38:49.250 --> 38:50.030] Right? [38:50.250 --> 38:53.510] And so if it... where I might bring this full circle is... [38:53.930 --> 38:59.550] Were one of you or somebody who listened to this to be in a meeting where somebody would argue, no, the computer will work. [38:59.710 --> 39:02.490] There will be an emergency door that unlocks if there's ever an emergency. [39:03.030 --> 39:04.850] Somebody needs to put their foot down and say, no. [39:05.170 --> 39:08.610] You know, there has to be a manual way of opening the emergency door. [39:08.750 --> 39:08.930] Period. [39:09.330 --> 39:15.350] Because I know that it's not possible to tell me, to convince me that the system will always be perfect. [39:15.350 --> 39:19.550] And if you can speak intelligently about why that is, you'll convince more people. [39:19.810 --> 39:21.210] You know, and you'll make a bigger difference. [39:23.050 --> 39:24.530] So, system bus weakness. [39:24.690 --> 39:26.730] And then I'm going to move on to the controller. [39:27.290 --> 39:28.450] The central controller. [39:30.150 --> 39:34.650] The system bus weaknesses, as I mentioned, they're very often standard buses. [39:36.710 --> 39:40.630] And it's easy to reveal what data and commands and so on are crossing them. [39:42.130 --> 39:44.190] You can do them with off-the-shelf tools. [39:44.890 --> 39:48.510] And in fact, it's one of the reasons why this topic is so germane right now. [39:48.750 --> 39:51.910] To me, it's become something I've become a bit more excited about. [39:52.050 --> 39:59.790] Because it used to be that even for me, to convince my company to buy me a multi-thousand dollar bus analyzer. [40:00.350 --> 40:02.570] You know, a ten or twenty-thousand dollar bus analyzer. [40:02.690 --> 40:04.630] Would be a little bit hard for me to pull off. [40:04.630 --> 40:07.770] And that's a level of obscurity that you have to respect. [40:08.170 --> 40:11.270] You know, not everybody is willing to spend that kind of money. [40:11.390 --> 40:13.850] That narrows the number of people down quite a lot. [40:14.090 --> 40:16.730] But nowadays, Pentium PCs are so fast. [40:17.510 --> 40:23.090] And, heck, you can run a Linux cluster and get some really good cranking power going there. [40:23.090 --> 40:27.150] And, as well, embedded systems have become so fast. [40:27.410 --> 40:32.190] That now, what you can buy is just a little box with a few wires coming out of it that samples the inputs. [40:32.610 --> 40:37.250] And has a high-speed connection to the computer where you have some software. [40:37.250 --> 40:38.490] And you've got a bus analyzer. [40:39.050 --> 40:46.450] So, for a hundred bucks or two hundred bucks, you have something that five or ten years ago was a ten or twenty-thousand dollar piece of equipment. [40:47.170 --> 40:47.750] All right. [40:47.890 --> 40:53.930] So, now it separates those in the know from those that are obscured from knowing it. [40:54.070 --> 40:58.870] Well, a couple hundred bucks and a little class at the community college. [40:59.090 --> 40:59.370] Really. [40:59.770 --> 41:01.650] You know, a few classes at the community college. [41:02.010 --> 41:03.670] And you're back to hacking again. [41:04.530 --> 41:16.170] And so, the days of having to be a rocket scientist, you know, to be able to break into hardware, they never existed, of course, because of all the bugs and the deadlines and everything we've talked about. [41:16.650 --> 41:19.650] But to actually even understanding it is not that hard anymore. [41:20.150 --> 41:23.690] And actually examining it and revealing what's going on inside is even easier. [41:24.050 --> 41:30.190] All you need are the usual concepts that you have already in terms of hacking. [41:30.670 --> 41:37.150] And perhaps that bridge, maybe this is it or maybe it's the class or whatever, that bridge to doing it. [41:37.230 --> 41:38.890] And you're into hardware hacking. [41:39.050 --> 41:39.890] It's that easy. [41:39.890 --> 41:44.450] And as I said, really 99% of the hardware hacking is just to make things better for the user. [41:45.030 --> 41:46.990] You know, something somewhere doesn't work the way you want it to. [41:47.150 --> 41:48.870] And so, you develop the skills that way. [41:49.170 --> 41:51.830] And sooner or later, they're widely available. [41:52.070 --> 41:57.370] And all it takes is some malcontent that knows how to use a crowbar to pop open a door and you've got it. [41:57.570 --> 42:02.370] And so, is the person that develops the technology the criminal? [42:02.570 --> 42:13.170] Well, if that were the case, crowbars and hammers, you know, because how good does a car alarm system need to be before you just bust the window and reach in and steal the purse if that's what you were after to begin with, you know? [42:13.310 --> 42:15.510] Or you tow away the car if it's that nice a car. [42:15.650 --> 42:18.070] I mean, yeah, that's pretty severe, towing a car. [42:18.330 --> 42:21.910] But I mean, how long does it take to pull a car up onto a trailer and drive off with it? [42:22.330 --> 42:24.510] You know, if you ask a professional, five minutes. [42:24.730 --> 42:26.210] You know, they can be out of there with that car. [42:26.210 --> 42:30.110] And how often have you seen a car pulled up on a tow truck and thought nothing of it? [42:30.690 --> 42:34.090] And so, how good does the security system need to be? [42:34.210 --> 42:39.630] Only as good, really, or a little bit better as the next obvious way of resolving it. [42:39.630 --> 42:42.210] You're still kind of left to yourself to solve the problem anyway. [42:43.810 --> 42:50.390] And so, with hacker mentality and hacker knowledge, everything suddenly seems easier. [42:51.770 --> 42:54.630] Sometimes you need some high-level knowledge because there are protocols used. [42:54.790 --> 43:00.630] So, if they're using TCP/IP, or they're using some RTOS, and so there's packets going back and forth over the network. [43:00.830 --> 43:04.850] There might be headers, and there might be filter numbers, and they might even be encrypting it. [43:05.030 --> 43:08.050] You know, you might feel that that level of attack is hopeless. [43:08.310 --> 43:10.690] And if it's a secure system, hopefully it is. [43:12.510 --> 43:14.830] But examples of, then, just bus analysis. [43:16.230 --> 43:17.910] An oscilloscope with a storage. [43:18.430 --> 43:21.210] You can buy them now for about $2,500 bucks. [43:23.170 --> 43:27.170] On the bottom right is the example that I gave with... [43:27.170 --> 43:31.030] Here's just a little piece of hardware connected to a computer. [43:31.370 --> 43:33.290] And this, then, is on the computer screen. [43:34.070 --> 43:36.250] Alright, so all the signals that you were looking at... [43:36.250 --> 43:38.090] This is like a $10,000 piece of equipment. [43:38.450 --> 43:40.830] These are all $5,000 and $10,000 pieces of equipment. [43:41.250 --> 43:43.570] Here, just a little piece of hardware, and you're doing the same thing. [43:43.670 --> 43:44.750] But now you're doing it on your computer. [43:45.150 --> 43:47.510] And you're back to the worlds of ones and zeros. [43:47.770 --> 43:49.790] And looking for patterns. [43:50.290 --> 43:51.090] And weaknesses. [43:51.530 --> 43:54.090] And trying to replicate things that you've seen over here. [43:54.370 --> 43:55.150] Back over there. [43:55.270 --> 43:56.550] And see if it can affect the behavior. [43:56.890 --> 43:58.850] And I'm going to, in fact, discuss some of that. [43:59.550 --> 44:02.910] And like I said, the bridge gets created. [44:03.110 --> 44:03.990] The gap is crossed. [44:04.150 --> 44:06.470] And now everybody has access to it. [44:06.510 --> 44:07.570] So now where's the obscurity? [44:07.670 --> 44:08.010] It's gone. [44:10.090 --> 44:13.250] Okay, so you've got this system. [44:13.570 --> 44:16.610] If you're really intent on breaking it. [44:16.930 --> 44:19.610] Somebody might argue, well, you know, you can encrypt the data. [44:20.150 --> 44:21.450] You can encrypt the buses. [44:21.690 --> 44:23.270] That's probably good enough. [44:23.270 --> 44:28.370] And if you start to hear the words, then you might think that you've really got it. [44:28.490 --> 44:29.370] The security is licked. [44:29.450 --> 44:30.150] It's taken care of. [44:30.210 --> 44:30.830] Everything's encrypted. [44:31.590 --> 44:32.770] Not true at all. [44:33.490 --> 44:37.350] There's just another level of obfuscation, of obscurity that you have to get through. [44:37.650 --> 44:39.750] But the real deal is still there to be had. [44:41.110 --> 44:43.190] And that's get at the source code. [44:43.670 --> 44:44.430] Well, there's a... [44:44.430 --> 44:47.050] How do you get at the source code on something that's a chip? [44:47.470 --> 44:50.950] Well, in similar ways that you might get to it in a computer. [44:51.270 --> 45:02.030] In a computer, a real hardware way of doing it, rather than having a software trick of like having a process emulator running that then ran a piece of software that you could halt and examine the software. [45:02.030 --> 45:11.550] A real hardware way of doing it would be to take the board, immobilize the processor that's running, keep the RAM refreshed, the DRAM, because it has to... [45:11.550 --> 45:18.170] You heard the Woz talk earlier about his board needed DRAM, because it was able to use fewer chips. [45:18.310 --> 45:20.150] Well, that's the standard still today for a lot of memory. [45:20.530 --> 45:24.270] So you keep the DRAM refreshed with another little circuit. [45:24.930 --> 45:26.850] Or if it's SRAM, you don't have to worry about it. [45:26.910 --> 45:30.030] And now you just start spooling out the contents of all the memory. [45:30.830 --> 45:33.850] You can access whatever was on the hard drive that needed to be done. [45:34.010 --> 45:35.070] And you've got the executable. [45:35.670 --> 45:38.110] And if there was any encryption algorithms, they're in there. [45:38.990 --> 45:42.850] And so if you can disassemble, now you can read the encryption algorithm. [45:43.210 --> 45:45.370] If you want to know how the encryption worked, you've got it. [45:46.050 --> 45:47.830] There's the blueprint right there for you. [45:48.490 --> 45:51.350] It's not very often done that way because there's easier ways. [45:51.350 --> 45:53.570] There's brute force methods and semi-intelligent. [45:53.730 --> 45:58.270] You saw perhaps the lockpicking where they found a way to get into the master. [45:58.470 --> 46:04.510] And so rather than crack every possible combination, by knowing a little bit about the system, they narrowed it down significantly. [46:05.010 --> 46:07.450] And this then is the same thing. [46:08.570 --> 46:13.330] Embedded systems, though, do have the tricky problem of the memory is on the chip. [46:13.330 --> 46:17.350] And so how do you get that memory out of the chip if the chip doesn't want you to have it? [46:18.030 --> 46:21.270] And that presents a bit more of a problem to crack. [46:22.090 --> 46:26.330] There are some, amazingly, some very easy ways to do that. [46:26.450 --> 46:28.590] And then there's some rather sophisticated ways. [46:30.110 --> 46:35.170] This is from a paper written by Sergey. [46:36.430 --> 46:42.210] And in his paper, he discusses the methods then for cracking hardware, for cracking a controller. [46:42.490 --> 46:43.550] It's executing a program. [46:43.550 --> 46:45.390] This is how we're going to attack it. [46:45.510 --> 46:50.670] And they are identical to every method that you understand about hacking. [46:51.390 --> 46:53.990] We're going to use microprobing techniques. [46:56.110 --> 47:00.430] In other words, we're going to look at exactly what it does. [47:00.590 --> 47:04.170] You know, we're examining what seems to go in it, what seems to come out of it. [47:04.930 --> 47:07.370] We can use an attack of some kind, right? [47:07.450 --> 47:12.190] Upset the thing and create an environment that it wasn't programmed for. [47:12.430 --> 47:19.210] We can just snoop it for long periods of time, eavesdrop on the thing, and see if you can't glean at least some information, right? [47:19.210 --> 47:24.790] That lockpicking analogy where he said once you had A key that worked, you could work your way to the master key. [47:24.830 --> 47:27.670] That really touched to the core of what we're talking about here. [47:27.850 --> 47:30.370] Because this might not crack it. [47:30.630 --> 47:31.970] That might not crack it. [47:32.290 --> 47:36.390] But the combined efforts, what you learn about, well, this is an I squared C bus. [47:36.630 --> 47:38.410] And there's data being put in an E squared. [47:38.670 --> 47:41.810] And I notice that data gets put to the E squared every time I do this. [47:42.310 --> 47:50.210] You know, I say, store the phone number or whenever I hold the button too long on the smoke detector, right? [47:50.270 --> 47:52.610] And all of a sudden there's this little flurry of activity on the E squared. [47:52.930 --> 47:54.550] And you begin to recognize this. [47:54.650 --> 47:56.570] Maybe there's a printer cartridge, right? [47:56.870 --> 48:00.090] Now printers are so cheap because the printer cartridges are so expensive. [48:00.330 --> 48:02.230] Well, why are the printer cartridges so expensive? [48:02.370 --> 48:04.690] Well, only one reason, because they can be, right? [48:04.790 --> 48:05.330] They're encrypted. [48:06.670 --> 48:07.630] They're hard to crack. [48:07.630 --> 48:12.430] And so now you're forced to buy these half empty printer cartridges for 40 and 50 bucks each. [48:13.030 --> 48:14.290] Because they're hard to crack. [48:14.570 --> 48:15.610] That's the only reason. [48:15.850 --> 48:18.430] And not because printer cartridges cost that much. [48:19.010 --> 48:20.970] But you can buy a printer cartridge and take it home. [48:21.190 --> 48:23.110] And you can figure out what's in it and how it works. [48:23.250 --> 48:25.810] And other printer cartridge companies do this very legitimately. [48:25.970 --> 48:30.750] Reverse engineer the Canon bubble jet printer cartridge and figure out how it works. [48:30.830 --> 48:34.470] And they do that in part, for instance, by examining the standard bus inside. [48:34.470 --> 48:38.650] It's got this funny thing it does with the printer that we can't figure out. [48:39.510 --> 48:41.530] But we found that it writes to this e-squared. [48:41.730 --> 48:45.230] And what it writes to the e-squared is how much ink is left. [48:45.650 --> 48:48.350] You know, well, if you just change that value every now and then, it's full. [48:48.450 --> 48:49.430] And you can keep filling it. [48:49.610 --> 48:51.150] Well, that's a workaround hack. [48:51.330 --> 48:55.490] But then, now that you begin to understand more about how it works, you can maybe affect it a little bit. [48:55.570 --> 49:02.010] You could even implement its functionality and trick the printer into thinking you have a legitimate ink cartridge in there. [49:02.010 --> 49:10.710] All right, so these eavesdropping and, of course, one of my favorites is fault generation, where you just throw everything at it and see what goes wrong. [49:11.070 --> 49:15.670] Seeing what goes wrong is one of the funnest ways to find out how something works. [49:16.670 --> 49:21.550] So, I mean, you can even relate that to social engineering, right? [49:21.750 --> 49:23.170] Or not only just computers. [49:23.430 --> 49:27.870] You sort of hang around and see how things work. [49:27.870 --> 49:32.790] Maybe you try to get in through a couple of frontal assault attacks. [49:33.430 --> 49:37.870] Maybe you just hang around and watch how other people get in and out and learn about what's going on. [49:38.150 --> 49:39.810] Or you create problems, right? [49:40.010 --> 49:43.470] False alarms or people dropping books or whatever. [49:43.830 --> 49:47.410] And all of a sudden, the security guards get all busy and the doors half open and you're in. [49:47.910 --> 49:48.350] Right? [49:48.530 --> 49:56.810] So, even these kinds of techniques, these are the four things that you almost always see everybody use as the method for figuring out how something works. [49:58.650 --> 50:00.810] Specifically then, cracking microcontrollers. [50:01.650 --> 50:03.170] Because these things are in everything. [50:03.390 --> 50:07.650] My phone, as I said, the microphone, the HVAC panel. [50:07.890 --> 50:13.810] And they're amazingly prolific and quite easy, really fairly easy to crack quite a lot of them. [50:14.090 --> 50:16.370] And this guy has written a paper on how to do it. [50:16.450 --> 50:18.810] And he depends upon a certain laws of physics. [50:19.110 --> 50:21.010] And one of them is having to do with transistors. [50:21.730 --> 50:24.290] Transistors have voltage levels that they operate correctly at. [50:25.150 --> 50:28.410] If you get down below their voltage level, they don't behave like they're supposed to. [50:29.010 --> 50:35.990] And if you can make them behave like they're not supposed to enough times, you might be able to make the whole circuit behave like it's not supposed to. [50:36.330 --> 50:39.150] And so, crack number one is mess with the power supply. [50:39.970 --> 50:50.110] Just start putting noise on the power supply, making the power supply jump up and down, putting noise in on the data lines and seeing what happens. [50:50.490 --> 50:54.730] And like I said, you might suddenly see a spur of activity, a burst of activity that you've never seen before. [50:55.050 --> 51:01.770] And so, you narrow down the noise and finally you figure out that this happening here and that happening there causes this to happen. [51:02.390 --> 51:06.030] They call it the technique fingerprinting in some cases. [51:06.270 --> 51:11.090] Where you've sort of taken a little electronic fingerprint of how it behaves with certain inputs. [51:11.530 --> 51:13.570] Well, he does this with this little box. [51:13.710 --> 51:17.170] He's got all these wires that lead to every lead on the microcontroller. [51:17.390 --> 51:19.410] And he can control the signals to every wire. [51:19.710 --> 51:23.670] And he's got a battery of tricks that he's learned that begins to work. [51:24.070 --> 51:27.170] And with that, he's cracked all these microcontrollers. [51:28.690 --> 51:29.130] Okay. [51:30.550 --> 51:37.770] One of the reasons why I don't need to go into a lot of detail exactly on how to do this is because it's a science in and of itself. [51:39.650 --> 51:43.970] Reverse engineering somebody else's product is something that many, many, very large companies do. [51:44.690 --> 51:55.130] And in fact, legally, reasonably, if you've lost the source code to your own product and you absolutely need a way to get a copy of it, is it illegal for you to get a copy of your own source code? [51:55.610 --> 52:05.910] So, if you hire a company capable of doing this for the perfectly legitimate reason of cracking your source code back out of it, why you couldn't be arrested, so therefore the tools are legitimate. [52:06.330 --> 52:09.350] And that sounds like a sneaky way around, but the fact is there's a lot of that. [52:09.510 --> 52:16.390] That's a very important aspect of reverse engineering and design are the tools that it takes to be able to do this, creating noise on pins. [52:17.010 --> 52:21.730] Goodness, if there was legislation created that you couldn't design a circuit that did that, almost nothing could be made. [52:22.610 --> 52:26.070] Well, you're not allowed to build something that can wiggle the inputs on pins. [52:26.910 --> 52:28.370] You know, well then throw it out. [52:28.830 --> 52:30.570] Go back to the dark ages now. [52:32.490 --> 52:33.370] So, he's... [52:34.450 --> 52:36.510] Well, you can just search on... [52:37.050 --> 52:48.450] Actually, on Sergei, the name that I mentioned in the previous slide, on his paper, Skorobogotov. [52:49.450 --> 52:51.710] I know I haven't done justice to it. [52:51.710 --> 52:58.110] And I actually have the link, www.cl.cam.ac.uk. [52:58.470 --> 53:02.110] You're probably pulling this off the online version if you're doing anything with this. [53:02.670 --> 53:08.070] Slash tilde SPS32 slash MCU underscore lock dot html. [53:09.170 --> 53:11.050] I know you didn't get that in this room. [53:11.510 --> 53:14.110] So, Sergei wrote a paper on it. [53:14.150 --> 53:20.750] And it's actually a subject of research, breaking microcontrollers of Princeton University and MIT. [53:20.750 --> 53:24.910] You know, these companies, these universities are trying to develop better technologies. [53:25.610 --> 53:30.190] And so, of course, they're showing how these can be broken so they can demonstrate a better way of doing it. [53:30.530 --> 53:33.330] And therefore, this becomes a necessary means of research. [53:33.710 --> 53:37.030] So, like I said, there's a lot of really legitimate reasons to be able to do this. [53:37.230 --> 53:40.870] There's not a reason to be afraid of people who are doing this. [53:41.030 --> 53:42.670] You just need to be aware that this can be done. [53:43.710 --> 53:47.890] And so, another reason why hardware is not all that secure, really. [53:48.110 --> 53:51.530] You know, the tools available to get into it are just prolific. [53:53.410 --> 53:55.770] There are some more sophisticated techniques, though. [53:55.910 --> 53:59.310] And this you begin to see when industries attack each other. [53:59.510 --> 54:01.910] You know, corporations start to really do battle. [54:02.930 --> 54:05.870] Maybe something very popular comes out like the PlayStation 2. [54:06.730 --> 54:12.350] And maybe they've got this, what they call a MagicGate memory cartridge that you plug in. [54:12.550 --> 54:19.550] And anybody who owns a PlayStation 2 knows that you have to buy the Sony memory cartridge. [54:19.550 --> 54:21.270] And they're really expensive. [54:21.490 --> 54:27.290] In fact, amazingly so, compared to the same amount of memory on anything else. [54:27.750 --> 54:30.770] Standard memory for a camera or for an MP3 player. [54:31.310 --> 54:35.130] And wouldn't you just love to pay the real price of that piece of memory? [54:35.330 --> 54:39.390] And there's nothing illegal about buying a piece of memory that works in there. [54:39.530 --> 54:41.970] It's just very difficult to make one that will work. [54:41.970 --> 54:46.910] Because they've encrypted the data going back and forth with this MagicGate system. [54:46.910 --> 54:52.070] And so now you have companies whose industry is dependent upon reverse engineering that. [54:52.690 --> 54:55.590] Okay, and so they spend a lot of money with these kinds of techniques. [54:55.790 --> 54:57.470] You can do power consumption analysis. [54:57.470 --> 54:58.510] You can probe the chip. [54:58.690 --> 55:01.000] You can examine with infrared microscopes. [55:01.950 --> 55:03.910] And look at the traces inside the chip. [55:04.150 --> 55:06.410] The light coming off of the active traces. [55:06.630 --> 55:09.330] Just like buses and signals on a circuit board. [55:10.470 --> 55:13.850] Here is what's called a FIB, or a focused ion beam. [55:14.070 --> 55:15.690] Where you can actually rewrite the circuit. [55:15.690 --> 55:17.210] You can cut traces on a circuit. [55:17.530 --> 55:20.310] You can redraw the trace on a circuit. [55:20.470 --> 55:22.330] And rewire an integrated circuit. [55:24.630 --> 55:26.670] That you can build ICs with that. [55:26.850 --> 55:30.130] You can actually dope materials and create transistors. [55:30.410 --> 55:32.950] And there are actually very sophisticated companies. [55:33.170 --> 55:35.810] Where if you're a semiconductor manufacturer and you've screwed up. [55:35.930 --> 55:37.550] And you need to find out, will this fix it? [55:37.870 --> 55:39.650] You can come up with a fix. [55:39.830 --> 55:41.690] Send it off to a company to have it FIB. [55:41.690 --> 55:43.850] And they will build the transistors right on your die. [55:44.210 --> 55:45.510] To add this little change. [55:45.650 --> 55:46.070] Make a cut. [55:46.210 --> 55:46.690] Make a trace. [55:46.990 --> 55:48.230] And send you the die back. [55:48.330 --> 55:50.130] And now you can see if your fix will work. [55:50.970 --> 55:54.830] As can a person, company, or entity trying to reverse engineer an IC. [55:55.030 --> 55:56.070] And they want to break code protect. [55:56.350 --> 55:58.030] And they think maybe this line breaks it. [55:58.110 --> 55:59.110] Maybe this line breaks it. [55:59.530 --> 55:59.790] Alright. [55:59.990 --> 56:01.450] So then once you learn these techniques. [56:01.450 --> 56:03.650] They figured out they reverse engineered the product. [56:09.210 --> 56:10.970] How expensive is it to do that? [56:11.110 --> 56:11.670] Was the question. [56:12.350 --> 56:13.770] If there are companies in China. [56:16.030 --> 56:18.910] That reverse engineer so that they can manufacture the clone for you. [56:19.510 --> 56:19.590] You know. [56:19.770 --> 56:21.690] So you might, if you're going to make enough of them, get it for free. [56:23.310 --> 56:24.650] I'm out of time it looks like. [56:24.770 --> 56:26.390] So I'm just going to say one or two last things. [56:27.410 --> 56:31.310] The power supply analysis was just so you could look at the power going into it. [56:31.410 --> 56:35.990] And you can see which instructions are often being executed by how much power they draw. [56:36.790 --> 56:37.590] Address changes. [56:37.730 --> 56:38.990] Go-to's, fetches, calls. [56:39.110 --> 56:40.870] Change a lot of latch circuitry. [56:40.990 --> 56:46.510] And draw a lot more power than just really simple an add or subtract or something like that. [56:46.730 --> 56:49.150] So you can actually examine the power consumption of a chip. [56:49.310 --> 56:52.370] And figure out what kind of decryption routine it might be using. [56:52.370 --> 56:56.350] Because you see that it's looping or that it's just determined it always looks like noise. [56:56.610 --> 56:58.510] Or it has these repetitious cycles in it. [56:59.150 --> 57:02.970] I threw that in there because I was at the Museum of American History. [57:03.130 --> 57:07.030] And Mad Magazine has this cover from the 70's I think it was. [57:07.110 --> 57:07.490] 78. [57:08.030 --> 57:11.850] When they started forcing UPC symbols onto products. [57:12.070 --> 57:15.970] And they put this one up that says, We hope this issue jams every computer in the country. [57:16.950 --> 57:21.790] And it's that kind of thing that could actually work if you had sort of an inside knowledge. [57:21.790 --> 57:25.370] And I thought that was pretty clever of them to make their protests in that way. [57:25.510 --> 57:28.590] And the rest is just pointing out how these hacks are being done. [57:28.810 --> 57:29.650] Cut some traces. [57:29.970 --> 57:31.030] Insert a circuit board. [57:33.250 --> 57:35.870] The OnStar system has been hacked. [57:36.490 --> 57:39.050] You can use the GPS in it with your computer. [57:39.530 --> 57:41.790] You can use the computer system with your GPS. [57:41.790 --> 57:43.270] You can add a serial port. [57:43.970 --> 57:45.890] Because there's an embedded serial port to it. [57:47.130 --> 57:50.470] And some things that we might try to do to improve it. [57:51.410 --> 57:51.690] Security. [57:52.570 --> 57:53.610] Tamper proofing. [57:53.750 --> 57:54.250] Encryption. [57:54.550 --> 57:55.070] Authentication. [57:55.350 --> 57:56.070] And all of these things. [57:56.410 --> 57:58.670] But the best one is the last one here. [57:58.790 --> 58:01.470] Don't depend too much on hardware for ultimate security. [58:01.730 --> 58:06.050] You're just not going to achieve a final resolution if that's your mechanism. [58:07.190 --> 58:10.050] The near future embedded Ethernet. [58:10.870 --> 58:12.130] I wanted to let you guys know. [58:12.230 --> 58:13.490] Even though you're probably fully aware of it. [58:13.590 --> 58:17.070] But the manufacturers of microcontrollers are really gearing up with chips. [58:17.710 --> 58:20.070] With Ethernet Macphys on them. [58:20.450 --> 58:23.410] So the physical and the Mac layer are built into the chip. [58:23.670 --> 58:25.050] And everybody's coming out. [58:25.530 --> 58:27.490] And that precedes a flood of design. [58:27.490 --> 58:29.050] Which is going to precede a flood of products. [58:29.050 --> 58:34.170] And so you're going to see a lot of really hackable products coming out soon. [58:34.530 --> 58:38.590] And your voice over IP phone may be one of them. [58:39.030 --> 58:42.950] How does the legal issues affect us in this industry? [58:43.230 --> 58:46.630] The DMCA can make it illegal in some cases to reverse engineer. [58:47.510 --> 58:51.250] There are limits on encryption export and IC complexity export. [58:51.850 --> 58:53.530] A couple of things that bothered me. [58:53.670 --> 58:56.250] The GNU Radio Project has to worry about things like HDTV. [58:56.250 --> 58:58.110] Because they're able to build a universal circuit. [58:58.330 --> 58:59.990] That can bring in almost any frequency. [59:00.550 --> 59:02.490] They could theoretically bring in HDTV. [59:02.890 --> 59:04.050] Which we can't allow. [59:04.290 --> 59:06.450] Because somebody owns that. [59:06.650 --> 59:10.450] And they are supposed to charge you money for being able to decrypt that. [59:10.770 --> 59:12.610] And just being able to build your own decryption. [59:13.350 --> 59:14.790] Or Descrambler wouldn't be right. [59:15.430 --> 59:17.850] But even though that's not its expressed intention. [59:18.790 --> 59:20.870] My Altheros driver in my laptop. [59:21.130 --> 59:22.130] I can't get the Linux. [59:22.330 --> 59:23.690] The source code for the Linux driver. [59:23.690 --> 59:27.990] Because it's capable in software of having its frequency changed. [59:27.990 --> 59:29.630] Throughout the 2.4 gigahertz band. [59:30.410 --> 59:33.330] And so I could theoretically nefariously use that. [59:33.650 --> 59:36.010] If I could get at the source code and change the way it worked. [59:36.570 --> 59:38.490] Forgetting the fact that I can build a circuit to do that. [59:38.610 --> 59:41.610] I don't need the Linux driver to Atheros to do that. [59:41.970 --> 59:44.650] But still they've had problems being able to release the source code. [59:44.850 --> 59:46.050] Because people who don't understand. [59:46.670 --> 59:47.910] Get in the way of the progress. [59:48.110 --> 59:48.710] The real progress. [59:49.510 --> 59:51.430] FCC limitations on frequencies. [59:52.850 --> 59:55.370] Narrowed down the range of where you'll find buses connected. [59:55.970 --> 59:56.470] And then finally. [59:57.350 --> 59:58.250] Go forth. [59:58.510 --> 59:58.870] Peace. [59:59.050 --> 59:59.310] Happiness. [59:59.510 --> 01:00:00.750] Hope everybody's having a good time. [01:00:01.290 --> 01:00:02.650] I had a really great time. [01:00:03.130 --> 01:00:04.750] Hopefully you use the information for good. [01:00:05.550 --> 01:00:06.690] That's what I would ask. [01:00:06.890 --> 01:00:10.270] And I don't accept invitations to crack anybody's system. [01:00:10.270 --> 01:00:13.350] But you're welcome to write to me or give me a call. [01:00:13.770 --> 01:00:14.190] Thanks.