BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Texas Incidents - How we broke the OMAP-L138 Trusted
  Execution\n   Environment\n   Tags: DEF CON Official Talk | Demo 💻\n  
  When: Friday\, Aug 7\, 10:00 - 10:59 PDT\n   Where: LVCCW Level 1 Hall 3 
 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\n   In this ta
 lk\, we'll discuss how we achieved the black-box compromise\n   of the Tru
 sted Execution Environment (TEE) of the Texas Instruments\n   OMAP-L138\, 
 a popular SoC encountered in various PMR radios\, satcom\n   equipment and
  other embedded applications. These radios are frequently\n   used in safe
 ty-critical roles\, where integrity and service\n   availability is paramo
 unt.\n\n   Through a painstaking iterative process\, which includes buildi
 ng both\n   a disassembler and a decompiler for the (hellish) DSP architec
 ture\,\n   and through blind exploitation of the Texas Instruments ROM cod
 e\n   underpinning the TEE functionality\, we managed to abuse a (novel ty
 pe\n   of) timing side channel that exists when attempting to load (bogus)
 \n   cryptographic modules into the TEE\, allowing us to recover the\n   m
 anufacturer key within a minute.\n\n   The talk dives deep into the techni
 cal aspects of the attack\,\n   providing a rare perspective on how the si
 mple primitive of\n   "decryption isn't constant time" can ultimately be l
 everaged into a\n   very tangible result: recovery of the device's full 12
 8-bit AES key.\n   Additionally\, we discuss several ROM-based vulnerabili
 ties\, including\n   one that enables full secure-mode code execution on t
 he SoC.\n\n   Vulns are in ROM\, so if you're so inclined: feel free to ha
 ve fun with\n   those on other OMAP-L138-powered devices.\n\n   Speakers:C
 arlo Meijer\,Wouter Bokslag\n\n   SpeakerBio:  Carlo Meijer\, Midnight Blu
 e\n\n   Carlo Meijer is a founding partner of the boutique security\n   co
 nsultancy firm Midnight Blue and is most known for his research into\n   T
 ETRA\, the MIFARE Classic Crypto1 RFID cipher\, and the security of\n   se
 lf-encrypting drives. Furthermore\, Carlo regularly competes in the\n   fa
 mous Pwn2Own hacking competition\, where he is part of team PHP\n   Hoolig
 ans.\n\n   SpeakerBio:  Wouter Bokslag\, Midnight Blue\n\n   Wouter Boksla
 g is a co-founding partner and security researcher at\n   Midnight Blue. H
 e is known for the reverse-engineering and\n   cryptanalysis of several pr
 oprietary in-vehicle immobilizer\n   authentication ciphers used by major 
 automotive manufacturers as well\n   as co-developing the world’s fastes
 t public attack against the\n   Hitag2 cipher. He holds a Master’s Degre
 e in Computer Science &\n   Engineering from Eindhoven University of Techn
 ology (TU/e) and\n   designed and assisted in teaching hands-on offensive 
 security classes\n   for graduate students at the Dutch Kerckhoffs Institu
 te for several\n   years.\n\n   Recently heavily involved in the TETRA:BUR
 ST research and associated\n   follow-up research\, such as the recent rev
 erse-engineering and\n   analysis of the elusive TETRA End-to-End protocol
 . Also\, a contributer\n   of open-source SDR code.\n\n   '\n\n   1. #LVCC
 W_Level1_Hall3\n\n\n
DTEND:20260807T175900Z
DTSTART:20260807T170000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Texas Incidents - How we broke the OMAP-L138 Trusted Execution Envi
 ronment
END:VEVENT
END:VCALENDAR
