Welcome Matt Brown of Brown Fine Security!
Matt has been reverse engineering a “smart” smoker controller that talks back to AWS IOTJeff Geerling talking about his dishwasherStoring private keys on the device??Threat modelsKey rotationWhat is the best case scenario for an IoT device?Secure boot / trust zoneKeys encrypt flash storageChris has designed in the ATECC608 beforeReplacing Certificate Authority (CA) cert in grill firmwareMatt has a Linux hardware / reverse engineering backgroundFlash is always externalGhidra / idapro / binwalkSecurity cameras are 99% linux based (battery based cameras might be embedded)Best practicesEncrypted firmwarehidden uart / jtagKeysAre linux devices “worth more” to a security researcher?CVSS risk scoring systemAttack vectorVulnerabilities are better if it can be a remote executedLinux devices have more computeBluetoothe LEAbility to enumerateScale reverse engineeringChris has discussed the silliness of a bluetooth toothbrush on the show beforeTools / Software of the tradexgeku firmware readerpicoempPCBiteSaleaeSDR USRP B200Universal radio hackerStick-to-it-nessMatt just came back from hardwear.io, one of his new favorite conferencesFind Matt at the embedded systems village at DEF CONFollow Matt via his YouTube channelMatt has a new IoT Security newsletter starting up