01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates

Black Hat USA 2014: Think Hard

Code can always change, but silicon is forever... more or less. Today's quartet of Black Hat Briefing highlights, which will all take place at Black Hat USA 2014, examine security with a focus on the hard stuff.

It's always fun when a solution for one issue can be repurposed to solve another problem. Creating a Spider Goat: Using Transactional Memory Support for Security brings us another example, in which the presenters bent the Transactional Synchronization Extension (TSX) memory conflict avoidance features of modern Intel CPUs toward security purposes. Used this way, TSX can detect malicious RAM modifications with minimal overhead. They'll also address potential problems of this unofficial use case.

The last decade's seen great advances in secure software development practices, but secure hardware development remains essentially undefined. Most hardware doesn't bother with security routines, or it keeps them obfuscated and secretive. SecSi Product Development: Techniques for Ensuring Secure Silicon Applied to Open-Source Verilog Projects aims to get that ball rolling, documenting pre- and post-silicon validation techniques and applying them to various open-source core designs while classifying various hardware security bugs into several categories.

The Bluetooth-, IR-based Super iBox BT, popular among real estate professionals, is a physically hardened device that stores a door key and contains a hardened MSP430 with a blown JTAG fuse. Is this still a large obstacle? In Reverse-Engineering the Supra iBox: Exploitation of a Hardened MSP430-Based Device, Braden Thomas will present his findings, giving an update on Goodspeed's 2008 bootstrap attacks and ultimately demonstrating how to perform firmware extraction reliably on such boxes. His newly developed attack can open any iBox, despite their complex and surprisingly effective crypto key management scheme.

Speaking of keys, How to Wear Your Password will present a new authentication paradigm that achieves both a desirable user experience and a high level of security. The security bracelet in question has a low-power processor, a Bluetooth LE transmitter, an accelerometer, and a clasp that detects wearer presence or lack thereof. Expect a thorough case study, complete with discussion of the physical design, the lightweight security protocols needed for pairing, determination of user intent, credential management, safeguards against violent attacks on the wearer, and the security implications of the design.

Regular registration ends on July 26. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-09
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Published: 2015-10-09
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

Published: 2015-10-09
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.