BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Raiders of the Lost Firmware: A Hands-On Workshop in
  IoT\n   Firmware Archaeology\n   Tags: IoT Village | Creator Talk/Panel\n
    When: Saturday\, Aug 8\, 12:30 - 13:30 PDT\n   Where: LVCCW Level 1 Hal
 l 3 1105 (Creator Stage 3) - [1]Map\n\n   Description:\n\n   Modern IoT fi
 rmware often appears protected behind proprietary\n   encryption\, stoppin
 g analysis before it starts. However\, in many cases\n   the fastest path 
 forward is not to break the cryptography\, but it is\n   to reuse the vend
 or’s own implementation via targeted function\n   emulation. In this han
 ds-on workshop\, attendees will learn a\n   methodology we call firmware a
 rchaeology: a practical method for\n   reconstructing the proprietary firm
 ware decryption scheme by\n   correlating artifacts left behind across fir
 mware archives\, public\n   repositories and developer ecosystems. Attende
 es will analyze the\n   real-world ecosystem of a commercial IP camera ven
 dor\, using the\n   firmware archaeology methodology. First\, they will id
 entify historical\n   artifacts and ecosystem components from publicly ava
 ilable sources.\n   Next\, they will recover from binaries the cryptograph
 ic routines that\n   are responsible for decrypting the firmware images. T
 hey will then\n   reuse and emulate these functions in a controlled enviro
 nment to\n   recover the decrypted firmware image that was initially secur
 ed by the\n   proprietary encryption scheme. With this access\, participan
 ts will\n   move beyond decryption to explore hidden functionalities of th
 e target\n   device and map the broader attack surface of the platform tha
 t was\n   previously inaccessible. The workshop is designed as a practical
 \n   methodology session rather than a one-off trick or a showcase of\n   
 vulnerabilities. All exercises are hands-on and based on real\n   research
 \, with pre-packaged material and tooling provided. Attendees\n   will lea
 ve with a practical and repeatable methodology for analyzing\n   modern Io
 T platforms\, including techniques to reconstruct firmware\n   decryption 
 pipelines and bypass analysis barriers without\n   reimplementing vendor c
 ryptography from scratch.\n\n   Speakers:Simone Bossi\,Luca Borzacchiello\
 n\n   SpeakerBio:  Simone Bossi\n\n   Simone takes apart embedded systems 
 and firmware for a living\, but it\n   took a while to get there. He start
 ed doing vulnerability research in\n   2015 on web\, mobile\, network\, an
 d the occasional cryptography rabbit\n   hole\, including a stint as a cry
 ptanalyst at STMicroelectronics\n   working on IoT communications security
 . Around 2020 he moved fully\n   into IoT and OT\, where bugs live in prop
 rietary protocols\, firmware\n   nobody was meant to read\, and hardware t
 hat was built to last\, not to\n   be secured.\n\n   He now leads the vuln
 erability research team at Nozomi Networks Labs\,\n   where they find 0-da
 ys in industrial and IoT devices\, and quickly\n   learned that the most i
 nteresting features are the ones you don't find\n   in the user manual. Al
 ong the way: academic research on weaknesses in\n   Linux's cryptsetup and
  PBKDF2 that made it into the security\n   literature\, open-source offens
 ive tooling\, and RE sessions old enough\n   to have developed opinions.\n
 \n   SpeakerBio:  Luca Borzacchiello\, Nozomi Networks\n\n   Luca Borzacch
 iello is a Security Researcher with deep expertise in\n   Symbolic Executi
 on\, Reverse Engineering\, and Fuzzing. He currently\n   works at Nozomi N
 etworks\, where he focuses on cutting-edge security\n   research. Before j
 oining Nozomi\, Luca served as a Red Team Engineer\n   for the Italian Gov
 ernment\, where he contributed to national\n   cybersecurity initiatives. 
 He also worked as researcher on the Red\n   Team at TIM S.p.A.\, one of It
 aly’s leading telecommunications\n   companies. Luca holds a Ph.D. in Pr
 ogram Analysis from Sapienza\n   University of Rome. Outside of work\, he 
 is an active participant in\n   Capture The Flag (CTF) competitions\, wher
 e he enjoys applying his\n   reverse engineering skills in high-stakes cha
 llenges.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T203000Z
DTSTART:20260808T193000Z
LOCATION:IoT Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3)
SUMMARY:Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware A
 rchaeology
END:VEVENT
END:VCALENDAR
