<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on Colin O'Flynn</title><link>https://colinoflynn.com/posts/</link><description>Recent content in Posts on Colin O'Flynn</description><generator>Hugo</generator><language>en-ca</language><lastBuildDate>Sun, 11 May 2025 13:09:53 +0000</lastBuildDate><atom:link href="https://colinoflynn.com/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Announcing my "Small Scale Electronics Production" Book</title><link>https://colinoflynn.com/2025/05/announcing-my-small-scale-electronics-production-book/</link><pubDate>Sun, 11 May 2025 13:09:53 +0000</pubDate><guid>https://colinoflynn.com/2025/05/announcing-my-small-scale-electronics-production-book/</guid><description>&lt;p&gt;During the pandemic I started a project I long wanted to do, which is to write down many of my lessons learned around building a hardware business. While this has now taken much longer than planned, I&amp;rsquo;m approaching a (hopeful) end of the draft process over the next couple of months. In combination with my Amp Hour discussion with Chris Gammel, I thought it was a good time to &amp;ldquo;officially&amp;rdquo; announce this!&lt;/p&gt;</description></item><item><title>Modifying Welding Pedal for a Miller 6-Pin Connector (ArcCaptain Pedal)</title><link>https://colinoflynn.com/2025/03/modifying-welding-pedal-for-a-miller-6-pin-connector-arccaptain-pedal/</link><pubDate>Mon, 17 Mar 2025 02:45:53 +0000</pubDate><guid>https://colinoflynn.com/2025/03/modifying-welding-pedal-for-a-miller-6-pin-connector-arccaptain-pedal/</guid><description>&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;I bought a Miller 161 STH welder which has a little hand remote control included, and found it was more difficult to use. I wanted to try a welding pedal but the miller ones are much more expensive than other brands, like ArcCaptain, and I found the ArcCaptain one sturdy enough. This post is how you can adapt other welding pedals to the Miller 6-pin connector. I made a video about the process, this post has the reference material:&lt;/p&gt;</description></item><item><title>My 2003 Low Cost SMD Soldering Guide</title><link>https://colinoflynn.com/2025/01/my-2003-low-cost-smd-soldering-guide/</link><pubDate>Wed, 15 Jan 2025 12:03:46 +0000</pubDate><guid>https://colinoflynn.com/2025/01/my-2003-low-cost-smd-soldering-guide/</guid><description>&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;Back in 2003, I wrote a guide for&lt;a href="https://avrfreaks.net/"&gt; AVRFreaks.net&lt;/a&gt; about low-cost SMD soldering. I had never mirrored this to my website, but recently needed a more permanent link to it for a PCB introduction lecture.&lt;/p&gt;&lt;br /&gt;
&lt;!-- /wp:paragraph --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;The information may no longer be the most current (22+ years later!), but I wanted to keep an official mirror of it on my website. You can find it inline below:&lt;/p&gt;</description></item><item><title>Fixing Ubiquiti Dream Machine (UDM) SE Hard Drive Not Detected Errors</title><link>https://colinoflynn.com/2024/12/fixing-ubiquiti-dream-machine-udm-se-hard-drive-not-detected-errors/</link><pubDate>Wed, 11 Dec 2024 02:34:43 +0000</pubDate><guid>https://colinoflynn.com/2024/12/fixing-ubiquiti-dream-machine-udm-se-hard-drive-not-detected-errors/</guid><description>&lt;p&gt;My UDM SE can fit &lt;a href="https://help.ui.com/hc/en-us/articles/360037340954-UniFi-Storage-Requirements-and-Compatibility"&gt;various hard drives&lt;/a&gt;. Ubiquiti have decided to have a cool tray the hard drive snaps into &amp;amp; slides into the UDM, which also means you have to have a very good fit. As it turns out, the fit may not be good enough without shimming the drive out!&lt;/p&gt;
&lt;p&gt;I used a &lt;em&gt;Seagate Skyhawk 4TB Video 3.5 Inch SATA (ST4000VXZ16/ST4000VX016)&lt;/em&gt; drive, which is reported as being compatible. In sliding the drive in there was no spin-up sound. I then tried rebooting it &amp;amp; repositioning the drive several times, it wasn&amp;rsquo;t clear if the hot-swap should work or not. But there was &lt;em&gt;never&lt;/em&gt; a spin-up sound or a LED flashing on. Very annoying, especially if you are rebooting your houses internet for a &amp;ldquo;5 min project&amp;rdquo;!&lt;/p&gt;</description></item><item><title>Dumping Parallel NAND with Glasgow</title><link>https://colinoflynn.com/2024/04/dumping-parallel-nand-with-glasgow/</link><pubDate>Sun, 14 Apr 2024 23:00:05 +0000</pubDate><guid>https://colinoflynn.com/2024/04/dumping-parallel-nand-with-glasgow/</guid><description>&lt;p&gt;I recently got my Glasgow device, which is a rather impressive piece of tech. I followed the Windows installation instructions and it &amp;ldquo;Just Worked&amp;rdquo;, including installing the toolchain! On one computer I needed to use Zadig to force the driver to be &lt;strong&gt;libusbK&lt;/strong&gt;, but on another Windows computer it wasn&amp;rsquo;t needed. In this blog post, I&amp;rsquo;m going to explore a parallel NAND device that I wanted to dump, and find out how well Glasgow works.&lt;/p&gt;</description></item><item><title>RECON 2023: Adventures of My Oven (Pinocchio) with ChipWhisperer</title><link>https://colinoflynn.com/2023/06/recon-2023-adventures-of-my-oven-pinocchio-with-chipwhisperer/</link><pubDate>Fri, 09 Jun 2023 14:40:27 +0000</pubDate><guid>https://colinoflynn.com/2023/06/recon-2023-adventures-of-my-oven-pinocchio-with-chipwhisperer/</guid><description>&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;At &lt;a rel="noreferrer noopener" href="https://cfp.recon.cx/2023/talk/PNCTLT" target="_blank"&gt;RECON2023 I gave a talk about reverse engineering my Samsung Oven&lt;/a&gt;. This blog post has slides &amp;amp; links to information, with more to come! You can get a copy of the slides below:&lt;/p&gt;&lt;br /&gt;
&lt;!-- /wp:paragraph --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:file {"id":1086,"href":"https://colinoflynn.com/wp-content/uploads/2023/06/OFLYNN-RECON2023.pdf","displayPreview":true} --&gt;&lt;br /&gt;
&lt;div class="wp-block-file"&gt;&lt;object class="wp-block-file__embed" data="https://colinoflynn.com/wp-content/uploads/2023/06/OFLYNN-RECON2023.pdf" type="application/pdf" style="width:100%;height:600px" aria-label="OFLYNN-RECON2023"&gt;&lt;/object&gt;&lt;a id="wp-block-file--media-9b103ca6-f0df-45ad-af7e-ab5e9adde67c" href="https://colinoflynn.com/wp-content/uploads/2023/06/OFLYNN-RECON2023.pdf"&gt;OFLYNN-RECON2023&lt;/a&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2023/06/OFLYNN-RECON2023.pdf" class="wp-block-file__button wp-element-button" download aria-describedby="wp-block-file--media-9b103ca6-f0df-45ad-af7e-ab5e9adde67c"&gt;Download&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;!-- /wp:file --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;&lt;/p&gt;&lt;br /&gt;
&lt;!-- /wp:paragraph --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;Oven-Specific Stuff: &lt;a href="https://github.com/colinoflynn/samsung-ovens-deconstructed"&gt;https://github.com/colinoflynn/samsung-ovens-deconstructed&lt;/a&gt;&lt;br&gt;Python Loader for TMP91 Series: &lt;a href="https://github.com/colinoflynn/pytoshload"&gt;https://github.com/colinoflynn/pytoshload&lt;/a&gt;&lt;br&gt;Resource CD for TLCS900: &lt;a href="https://github.com/colinoflynn/Toshiba-TLCS-900-L-Resources"&gt;https://github.com/colinoflynn/Toshiba-TLCS-900-L-Resources&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;</description></item><item><title>Intel LGA1700 (12th/13th gen, i9 3900k) Top Resistors/Capacitors</title><link>https://colinoflynn.com/2023/03/intel-lga1700-12th-13th-gen-i9-3900k-top-resistors-capacitors/</link><pubDate>Thu, 16 Mar 2023 01:46:06 +0000</pubDate><guid>https://colinoflynn.com/2023/03/intel-lga1700-12th-13th-gen-i9-3900k-top-resistors-capacitors/</guid><description>&lt;p&gt;If you&amp;rsquo;re a bit careless with your CPU (especially if e.g., delidding it) you can knock these resistors off the topside. From measuring a known-good device (but without removing them) I measured the following values as a reference:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2023/03/image.png"&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2023/03/image.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;i9 13900K image source: techpowerup.com&lt;/p&gt;
&lt;p&gt;These all appear to be 0402 sized resistors.&lt;/p&gt;
&lt;p&gt;If you do damage them, the &lt;em&gt;best&lt;/em&gt; source would be another 12th/13th gen device, as they look to be identical. You could find a used/defective low-performance device and use that to get resistors/capacitors.&lt;/p&gt;</description></item><item><title>Danni Build - Feb 11/23</title><link>https://colinoflynn.com/2023/02/danni-build-feb-11-23/</link><pubDate>Sat, 11 Feb 2023 13:50:40 +0000</pubDate><guid>https://colinoflynn.com/2023/02/danni-build-feb-11-23/</guid><description>&lt;p&gt;&lt;!-- wp:list --&gt;&lt;br /&gt;
&lt;ul&gt;&lt;!-- wp:list-item --&gt;&lt;br /&gt;
&lt;li&gt;Hours: 8&lt;/li&gt;&lt;br /&gt;
&lt;!-- /wp:list-item --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:list-item --&gt;&lt;br /&gt;
&lt;li&gt;Parts complete: 1 (lateral support), 2 (cylinder support), 3 (frame base)&lt;/li&gt;&lt;br /&gt;
&lt;!-- /wp:list-item --&gt;&lt;/ul&gt;&lt;br /&gt;
&lt;!-- /wp:list --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:image {"id":1070,"sizeSlug":"full","linkDestination":"media"} --&gt;&lt;br /&gt;
&lt;figure class="wp-block-image size-full"&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2023/02/image-1.png"&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2023/02/image-1.png" alt="" class="wp-image-1070"/&gt;&lt;/a&gt;&lt;figcaption class="wp-element-caption"&gt;Test assembly of three parts built today. The parts come pre-milled, so this was mostly time spent getting setup.&lt;/figcaption&gt;&lt;/figure&gt;&lt;br /&gt;
&lt;!-- /wp:image --&gt;&lt;/p&gt;
&lt;p&gt;&lt;!-- wp:paragraph --&gt;&lt;br /&gt;
&lt;p&gt;Start of build. Lots of marking &amp;amp; drilling of items, which was done on a milling machine with DRO. Having the DRO read-out is useful here rather than marking pieces I found. I had mounted cheap&lt;a href="https://www.youtube.com/watch?v=gUAQUITKijY" data-type="URL" data-id="https://www.youtube.com/watch?v=gUAQUITKijY"&gt; iGaging DROs to a small X2 mini-mill, there is a YouTube Video of how I did this&lt;/a&gt;. Here is drilling some holes in part 1:&lt;/p&gt;</description></item><item><title>New England Hardware Security Day 2022 Talk</title><link>https://colinoflynn.com/2022/04/new-england-hardware-security-day-2022-talk/</link><pubDate>Fri, 01 Apr 2022 11:50:25 +0000</pubDate><guid>https://colinoflynn.com/2022/04/new-england-hardware-security-day-2022-talk/</guid><description>&lt;p&gt;On April 1st, 2022 I gave a &amp;ldquo;workshop&amp;rdquo; at &lt;a href="http://vernam.wpi.edu/nehws22/"&gt;New England Hardware Security Day&lt;/a&gt;. This blog post is a quick summary of some of the links to recreate my demos from that talk. Here is a copy of the slides if you&amp;rsquo;d like them:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2022/04/New-England-Hardware-Security-Day-2022.pdf"&gt;New-England-Hardware-Security-Day-2022&lt;/a&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2022/04/New-England-Hardware-Security-Day-2022.pdf"&gt;Download&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="dfa-on-raspberry-pi-with-picoemp"&gt;DFA on Raspberry Pi with PicoEMP&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2022/04/image.png"&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2022/04/image.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Pi on Pi Violence&lt;/p&gt;
&lt;p&gt;This demo is pretty simple - it recreates the classic DFA attack on RSA (I find &lt;a href="https://www.cryptologie.net/article/371/fault-attacks-on-rsas-signatures/"&gt;David&amp;rsquo;s description great here&lt;/a&gt;, or you can see my &lt;a href="https://nostarch.com/hardwarehacking"&gt;Hardware Hacking Handbook&lt;/a&gt; which includes another derivation of it using a different method).&lt;/p&gt;</description></item><item><title>Apple AirTag Teardown &amp; Test Point Mapping</title><link>https://colinoflynn.com/2021/05/apple-airtag-teardown-test-point-mapping/</link><pubDate>Sat, 08 May 2021 18:24:32 +0000</pubDate><guid>https://colinoflynn.com/2021/05/apple-airtag-teardown-test-point-mapping/</guid><description>&lt;p&gt;&lt;a href="https://colinoflynn.com/wp-content/uploads/2021/05/IMG_3064.jpeg"&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2021/05/IMG_3064.jpeg" alt=""&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;What&amp;rsquo;s inside of Apple&amp;rsquo;s new AirTag? There was already an &lt;a href="https://www.ifixit.com/News/50145/airtag-teardown-part-one-yeah-this-tracks"&gt;iFixIt teardown&lt;/a&gt; (which I swear was missing a few items that are there now), but of course was curious to see what sort of protection was enabled. Notably the nRF chip used is likely vulnerable to a &lt;a href="https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/"&gt;known bypass of security&lt;/a&gt; as well. With that in mind, I set out to see how we could dump some data from this thing - the good news is you can access a lot of interesting stuff (including the SPI flash) right from the backside, which requires you to simply pop the first plastic cover off. This is super-easy to do without damaging anything. Going further than that is tricky to keep it all intact.&lt;/p&gt;</description></item><item><title>Analog Discover Pro Teardown</title><link>https://colinoflynn.com/2021/04/analog-discover-pro-teardown/</link><pubDate>Sat, 17 Apr 2021 16:14:13 +0000</pubDate><guid>https://colinoflynn.com/2021/04/analog-discover-pro-teardown/</guid><description>&lt;p&gt;NOTE: This was going to be a twitter thread but &lt;a href="https://twitter.com/TwitterSupport/status/1383436102577442835"&gt;twitter was down&lt;/a&gt;? So this is a lazy blog post&amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cdn11.bigcommerce.com/s-7gavg/images/stencil/1280x1280/products/666/5589/ADP3450-Obl-1000__34474.1611688929.png?c=2" alt="Analog Discovery Pro 3000 Series: Portable High Resolution Mixed Signal Oscilloscopes - Digilent"&gt;&lt;/p&gt;
&lt;p&gt;Analog Discovery Pro (from Digilent Website)&lt;/p&gt;
&lt;p&gt;Anyone used to Digilent would expect this to be based on Zynq or similar - the fact the device has USB + ethernet ports makes it a pretty much sure thing! Taking the screws off the bottom gives us this view:&lt;/p&gt;</description></item><item><title>Experimenting with Metastability and Multiple Clocks on FPGAs</title><link>https://colinoflynn.com/2020/12/experimenting-with-metastability-and-multiple-clocks-on-fpgas/</link><pubDate>Sat, 26 Dec 2020 22:58:43 +0000</pubDate><guid>https://colinoflynn.com/2020/12/experimenting-with-metastability-and-multiple-clocks-on-fpgas/</guid><description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;NOTE: This article appeared in Issue 293 of Circuit Cellar, back in December 2014. I’ve posted it here for your reading pleasure as well. References to previous articles are for Circuit Cellar Issues, as this was originally written for the print publication. This version differs slightly from the print version – this is my own ‘author copy’ version before the Circuit Cellar editing&lt;/strong&gt;&lt;/em&gt;. &lt;strong&gt;References to &amp;ldquo;ProgrammableLogicInPractice.com&amp;rdquo; are broken for now, but material has been mirrored to the bottom of this page.&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>BAM BAM!! On Reliability of EMFI for in-situ Automotive ECU Attacks</title><link>https://colinoflynn.com/2020/11/bam-bam-on-reliability-of-emfi-for-in-situ-automotive-ecu-attacks/</link><pubDate>Sun, 08 Nov 2020 21:50:11 +0000</pubDate><guid>https://colinoflynn.com/2020/11/bam-bam-on-reliability-of-emfi-for-in-situ-automotive-ecu-attacks/</guid><description>&lt;p&gt;This post is a summary of some work on an accepted paper for ESCAR EU 2020. This work was demonstration on certain NXP chips &amp;amp; GM ECUs, but the idea of both the attack &amp;amp; understanding how portable results are is applicable across the entire domain.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;NOTE TO CAR TUNERS: I won&amp;rsquo;t perform this for hire on your ECU,&lt;/strong&gt;&lt;/em&gt; &lt;em&gt;please don&amp;rsquo;t email me asking this.&lt;/em&gt; &lt;em&gt;&lt;strong&gt;The cost for me to do this type of work under hire would also be many times the HPTuners fee,&lt;/strong&gt;&lt;/em&gt; &lt;em&gt;and without any of of the actual tuning interface (I&amp;rsquo;m only attacking the bootloader, I never ever built a reflash tool that would be needed, yet alone the mapping work etc).&lt;/em&gt;&lt;/p&gt;</description></item><item><title>FPGA Board Design Tips</title><link>https://colinoflynn.com/2020/08/fpga-board-design-tips/</link><pubDate>Tue, 04 Aug 2020 16:33:34 +0000</pubDate><guid>https://colinoflynn.com/2020/08/fpga-board-design-tips/</guid><description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;NOTE: This article appeared in Issue 315 of Circuit Cellar, back in October 2016. I&amp;rsquo;ve posted it here for your reading pleasure as well. References to previous articles are for Circuit Cellar Issues, as this was originally written for the print publication. This version differs slightly from the print version - this is my own &amp;lsquo;author copy&amp;rsquo; version before the Circuit Cellar editing.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Back in December 2015, I discussed how I solder BGA devices
(such as FPGAs) using a low-cost reflow oven. This article will discuss the
design of the FPGA board itself, which you could then assemble using the tips
in my previous article.&lt;/p&gt;</description></item><item><title>Square Terminal Teardown</title><link>https://colinoflynn.com/2020/04/square-terminal-teardown/</link><pubDate>Mon, 06 Apr 2020 13:30:57 +0000</pubDate><guid>https://colinoflynn.com/2020/04/square-terminal-teardown/</guid><description>&lt;p&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2020/04/overview_from_video.jpg" alt=""&gt;&lt;/p&gt;
&lt;p&gt;Part-way through the Square Terminal Teardown&lt;/p&gt;
&lt;p&gt;I recently tore down a square terminal (the one with the LCD screen) and wanted to share some of these results. I haven&amp;rsquo;t photographed everything as was mostly interested in how the secure areas of it are down. You can see an overview in the following video if you want to see how the whole thing fits together.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=pB8T5wZJLcM"&gt;https://www.youtube.com/watch?v=pB8T5wZJLcM&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Teardown of Square Terminal Video&lt;/p&gt;</description></item><item><title>Amazon Echo Dot Gen 3 - Microphone Disable Circuitry</title><link>https://colinoflynn.com/2020/01/amazon-echo-dot-gen-3-microphone-disable-circuitry/</link><pubDate>Sat, 18 Jan 2020 17:36:11 +0000</pubDate><guid>https://colinoflynn.com/2020/01/amazon-echo-dot-gen-3-microphone-disable-circuitry/</guid><description>&lt;p&gt;Have you been interested in the Echo Dot device? One feature they mention is that there is a microphone off button. I spent a few hours reverse engineering this, and recorded (in un-edited glory) the process:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://youtu.be/xH8LnK9hh6w"&gt;https://youtu.be/xH8LnK9hh6w&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The resulting schematic is shown below:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2020/01/schematic-1024x534.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt;The astute reader will note the only pin under direct control allows the disabling of the microphone, it cannot re-enable it. However - there is one more loophole to check.&lt;/p&gt;</description></item><item><title>A Call for Time Travel Resistant Cryptography (TTRC)</title><link>https://colinoflynn.com/2019/09/a-call-for-time-travel-resistant-cryptography-ttrc/</link><pubDate>Thu, 19 Sep 2019 02:16:08 +0000</pubDate><guid>https://colinoflynn.com/2019/09/a-call-for-time-travel-resistant-cryptography-ttrc/</guid><description>&lt;p&gt;At CHES 2019 [rump session], I presented my revolutionary talk on Time Travel Resistant Cryptography (TTRC). This is a hugely important area of research that has been widely ignored in academic work, and it&amp;rsquo;s time to finally make this right.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://colinoflynn.com/wp-content/uploads/2019/09/image-2-1024x573.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt;Why is this so critical? While Post Quantum Cryptography (PQC) gets NIST contests, and invested companies, nobody is considering TTRC. The general thought-process of PQC is that the existence of sufficiently powerful quantum computers is an open problem with no clear solution. BUT - if someone solves that problem (that is unclear is even physically possible to solve), it&amp;rsquo;s going to be hell on Earth for crypto implementations. Better safe than sorry.&lt;/p&gt;</description></item><item><title>USB Triggering &amp; Hacking</title><link>https://colinoflynn.com/2019/09/usb-triggering-hacking/</link><pubDate>Mon, 02 Sep 2019 01:50:39 +0000</pubDate><guid>https://colinoflynn.com/2019/09/usb-triggering-hacking/</guid><description>&lt;p&gt;This blog post covers several topics that I should have made independent posts about&amp;hellip; but anyway. Here we are. It&amp;rsquo;s September and I should have done this months ago.&lt;/p&gt;
&lt;h2 id="trezor--usb-hacking-updates-black-hat--woot"&gt;Trezor / USB Hacking Updates (Black Hat + WOOT)&lt;/h2&gt;
&lt;p&gt;I had an earlier blog post with details of the Trezor attack. It turns out this is more generic type of attack than I realized, so I extended this work into a WOOT paper as well. Quickly I thought I should update on that&amp;hellip;&lt;/p&gt;</description></item><item><title>FICHSA ChipWhisperer Tutorial Requirements</title><link>https://colinoflynn.com/2019/05/fichsa-chipwhisperer-tutorial-requirements/</link><pubDate>Mon, 06 May 2019 11:31:39 +0000</pubDate><guid>https://colinoflynn.com/2019/05/fichsa-chipwhisperer-tutorial-requirements/</guid><description>&lt;p&gt;At the FICHSA Conference (&lt;br&gt;
&lt;a href="https://fichsa.sise.bgu.ac.il/"&gt;https://fichsa.sise.bgu.ac.il&lt;/a&gt; ) I will be running a short workshop on ChipWhisperer using the ChipWhisperer-Nano.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A direct link to a Google Doc with the most up to date information is available here:&lt;/strong&gt; &lt;a href="https://docs.google.com/document/d/1IgDeGZ6d0FEYJbaF4a-KsBhdIHlMZg04-wQYUSZgnks/edit?usp=sharing"&gt;&lt;strong&gt;https://docs.google.com/document/d/1IgDeGZ6d0FEYJbaF4a-KsBhdIHlMZg04-wQYUSZgnks/edit?usp=sharing&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you want to fully play along, please bring a laptop with the following installed and setup:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;VirtualBox 5.x (5.2.28 is latest supported). You CANNOT use VirtualBox 6 due to some unknown incompatibility.&lt;/li&gt;
&lt;li&gt;VirtualBox Extension pack for version you installed (&lt;a href="https://download.virtualbox.org/virtualbox/5.2.28/Oracle_VM_VirtualBox_Extension_Pack-5.2.28.vbox-extpack"&gt;direct link&lt;/a&gt; to 5.2.28, does not depend on the host OS).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I will be (hopefully) posting a VirtualBox image once one is fully updated.&lt;/p&gt;</description></item><item><title>Glitching Trezor using EMFI Through The Enclosure</title><link>https://colinoflynn.com/2019/03/glitching-trezor-using-emfi-through-the-enclosure/</link><pubDate>Wed, 06 Mar 2019 15:13:45 +0000</pubDate><guid>https://colinoflynn.com/2019/03/glitching-trezor-using-emfi-through-the-enclosure/</guid><description>&lt;p&gt;As mentioned on the &lt;a href="https://blog.trezor.io/details-of-security-updates-for-trezor-one-firmware-1-8-0-and-trezor-model-t-firmware-2-1-0-408e59dc012"&gt;Trezor blog post&lt;/a&gt;, their latest security patch fixes a flaw I disclosed to them in Jan 2019. This flaw meant an attacker with physical access to the wallet can find the recovery seed stored in FLASH, and leave no evidence of tampering.&lt;/p&gt;
&lt;p&gt;This work was heavily inspired by the &lt;a href="http://wallet.fail"&gt;wallet.fail&lt;/a&gt; disclosure - I&amp;rsquo;m directly dumping FLASH instead of forcing the flash erase then dumping from SRAM, so the results are the same but with a different path. It also has the same limitations - if you used a password protected recovery seed you can&amp;rsquo;t dump that.&lt;/p&gt;</description></item></channel></rss>