cas cs591 topics in internet security kingpin ([email protected]) [l-zero-p-h-t] hardware and...

23
CAS CS591 Topics in CAS CS591 Topics in Internet Security Internet Security Kingpin ([email protected]) http://www.L0pht.com [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

Upload: myrtle-simon

Post on 18-Dec-2015

218 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

CAS CS591 Topics in CAS CS591 Topics in Internet SecurityInternet Security

Kingpin ([email protected])

http://www.L0pht.com [L-zero-P-H-T]

Hardware and Embedded System Security Pitfalls

Page 2: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

IntroductionIntroduction• The L0pht

– Origin– Mission– Members– Who am I?

Page 3: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

The L0pht - OriginThe L0pht - Origin

• Banded together in 1992

• Originally set out as a simple communal storage area

• Combination of everyone’s “junk” turned into gems

• From networks to watchdogs

• The security puzzle

Page 4: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

The L0pht - MissionThe L0pht - Mission

• Learn and explore

• Provide an unbiased soap-box for our views and beliefs on technology

• Give back to the network security community without playing favorites

• Have the place self perpetuate (pay for itself)

Page 5: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

The L0pht - MembersThe L0pht - Members

MudgeWeld Pond

KingpinJohn Tan

Brian OblivionSpace Rogue

SilicosisDildog

Page 6: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

KingpinKingpin

• Involved w/ L0pht since inception, 1992

• Electrical engineer, hardware hacker

• Dial-up/telephone systems

• Product design

Page 7: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

Hardware and Embedded Hardware and Embedded System Security PitfallsSystem Security Pitfalls

• Security problems aren’t just limited to software

• Consider all possibilities when interfacing with the outside world!

• Any design can have fundamental flaws

Page 8: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls

ApplicationsApplications

Simple Complex

Page 9: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 10: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 11: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 12: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 13: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 14: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 15: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 16: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 17: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 18: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 19: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 20: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 21: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 22: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls
Page 23: CAS CS591 Topics in Internet Security Kingpin (kingpin@L0pht.com)  [L-zero-P-H-T] Hardware and Embedded System Security Pitfalls