BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: TETRA tour de force: Jailbreaking digital radios and
  base\n   stations for fun and secrets\n   When: Sunday\, Aug 13\, 14:00 -
  15:15 PDT\n   Where: Caesars Forum - Forum - 130-134 - Track 3 - [1]Map\n
    Speakers:Carlo Meijer\,Jos Wetzels\,Wouter Bokslag\n\n   SpeakerBio:Car
 lo Meijer \, Founding Partner and Security Researcher at\n   Midnight Blue
 \n   Carlo Meijer is a co-founding partner and security researcher at\n   
 Midnight Blue. His research focuses on the analysis of cryptographic\n   s
 ystems deployed in the wild. He is known for his work on the security\n   
 of so-called Self-Encrypting Drives (SEDs). Furthermore\, he is known\n   
 for breaking a hardened variant of Crypto1\, the cipher used in the\n   Mi
 fare Classic family of cryptographic RFID tags. Finally\, he\n   co-author
 ed research into default passwords in consumer routers as\n   deployed by 
 ISPs in the Netherlands. He is a PhD researcher and\n   systems security l
 ecturer at the Radboud University (RU) in the\n   Netherlands.\n\n   Speak
 erBio:Jos Wetzels \, Founding Partner and Security Researcher at\n   Midni
 ght Blue\n   Jos Wetzels is a co-founding partner and security researcher 
 at\n   Midnight Blue. His research has involved reverse-engineering\,\n   
 vulnerability research and exploit development across various domains\n   
 ranging from industrial and automotive systems to IoT\, networking\n   equ
 ipment and deeply embedded SoCs. He has uncovered critical zero-day\n   vu
 lnerabilities in dozens of embedded TCP/IP stacks\, Industrial\n   Control
  Systems (ICS)\, and RTOSes.\n\n   He previously worked as a researcher at
  the Distributed and Embedded\n   Security group (DIES) at the University 
 of Twente (UT) in the\n   Netherlands where he developed exploit mitigatio
 n solutions for\n   constrained embedded devices deployed in critical infr
 astructure\,\n   performed security analyses of state-of-the-art network a
 nd host-based\n   intrusion detection systems and has been involved in res
 earch projects\n   regarding on-the-fly detection and containment of unkno
 wn malware and\n   APTs.\n\n   Twitter: [2]@s4mvartaka\n\n   SpeakerBio:Wo
 uter Bokslag \, Founding Partner and Security Researcher\n   at Midnight B
 lue\n   Wouter Bokslag is a co-founding partner and security researcher at
 \n   Midnight Blue. He is known for the reverse-engineering and\n   crypta
 nalysis of several proprietary in-vehicle immobilizer\n   authentication c
 iphers used by major automotive manufacturers as well\n   as co-developing
  the world's fastest public attack against the Hitag2\n   cipher. He holds
  a Master's Degree in Computer Science & Engineering\n   from Eindhoven Un
 iversity of Technology (TU/e) and designed and\n   assisted teaching hands
 -on offensive security classes for graduate\n   students at the Dutch Kerc
 khoffs Institute for several years.\n\n   Description:\n   In this talk we
  will discuss the radio jailbreaking journey that\n   enabled us to perfor
 m the first public disclosure and analysis of the\n   proprietary cryptogr
 aphy used in TETRA (Terrestrial Trunked Radio): a\n   standard used global
 ly by government agencies\, police\, prisons\, and\n   military operators 
 as well as critical infrastructure such as SCADA\n   telecontrol of oil ri
 gs\, pipelines\, transportation and electric and\n   water utilities.\n\n 
   For decades\, the underlying algorithms have remained secret under\n   r
 estrictive NDAs prohibiting public scrutiny of this critical\n   technolog
 y. In this talk\, we will make public the TETRA cipher suites\n   (TEA and
  TAA1 to be precise)\, one of the last bastions of widely\n   deployed sec
 ret crypto\, and discuss in-depth how we managed to obtain\n   them.\n\n  
  We will discuss several different flaws we uncovered allowing passive\n  
  or active adversaries to intercept and manipulate TETRA traffic\,\n   inc
 luding details of a backdoored stream cipher.\n\n   This journey involved 
 reverse-engineering and exploiting multiple\n   0-day vulnerabilities in t
 he popular Motorola MTM5x00 radio and its TI\n   OMAP-L138 TEE and covers 
 everything from side-channel attacks on DSPs\n   to writing your own decom
 pilers. We will also discuss how we gained\n   code execution on and instr
 umented a Motorola MBTS TETRA base station\n   for research purposes.\n\n 
   REFERENCES:\n\n     * Daniel J Bernstein. Cache-timing attacks on AES. 2
 005.\n\n     * Shuwen Duan. Security analysis of TETRA. Masterâ€™s thesis\
 ,\n       Institutt for telematikk\, 2013.\n\n     * Jonas Olofsson. Desig
 n and implementation of SIM functionality for\n       TETRA-system on a sm
 art card\, 2012.\n\n     * Yong-Seok Park\, Choon-Soo Kim\, and Jae-Cheol 
 Ryou. The\n       vulnerability analysis and improvement of the TETRA auth
 entication\n       protocol. 2010\n\n     * Martin Pfeiffer\, Jan-Pascal K
 wiotek\, Jiska Classen\, Robin\n       Klose\,and Matthias Hollick. Analyz
 ing TETRA location privacy and\n       network availability. 2016\n\n     
 * Marek Sebera TomáÅ¡ Suchan. TETRA networks security\, 2015.\n\n     * Zh
 i-Hui Zhang and Yi-Xian Yang. Research on endto-end encryption\n       of 
 TETRA. 2006\n\n     * Müller\, Uwe \; Hauck\, Eicke \; Welz\, Timm \; Clas
 sen\, Jiska \;\n       Hollick\, Matthias. Dinosaur Resurrection: PowerPC 
 Binary Patching\n       for Base Station Analysis. 2021\n\n   '\n\n   1. #
 CaesarsForumBR\n   2. https://twitter.com/s4mvartaka\n\n\n
DTEND:20230813T221500Z
DTSTART:20230813T210000Z
LOCATION:DC - Caesars Forum - Forum - 130-134 - Track 3
SUMMARY:TETRA tour de force: Jailbreaking digital radios and base stations 
 for fun and secrets
END:VEVENT
END:VCALENDAR
