stacksmashing

@stacksmashing.bsky.social

Security researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of hextree.io. Contact: contact@stacksmashing.net

If there's one hardware wallet I always told people not to trust it's COLDCARD. Not surprised in the slightest by the recent events. (They messed up their RNG in multiple ways, leading to - so far - user losses above $38 million USD.)

My DEF CON talk "Hacking jetskis - from Sea-Don't to Sea-Doo" got accepted 🥳 We'll be having some good fun - such as bypassing the immobilizer using a custom Flipper Zero app, building a custom diagnostic adapter, and some big plot-twists 🛥️

Flipper showing Jetski diagnostic info

Sometimes it’s nice to go back to basics: Built firmware that’s just 246 bytes, uses no RAM at all, and runs parasitically from a 1-wire bus at just 0.2 mA. Yet it emulates a full jetski key! You can see voltage rising until the chip starts running based on the BOD threshold.

BildBild

Simple age check for Linux: Just have the shell ask the user to check the host IP on first boot. If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇

My first post on the RaspberryPi Blog 😍 We've extended the RP2350 side-channel hacking challenge to April 30 - and even better: To make attacks for the challenge easier, we decided to disable the random chaffing and some more mitigations! www.raspberrypi.com/news/rp2350-...

RP2350 Hacking Challenge 2: Less randomisation, more correlation - Raspberry Pi

Our second RP2350 Hacking Challenge has evolved, with prize money still up for grabs.

raspberrypi.com

En route to #39c3 - come to our talk at 4pm! I will only be there today and tomorrow, but happy to meet-up & chat. Also, if you are at #39c3 and often dump SPI flash-chips please let me know, I might have something for you that I'm looking for feedback on 🙂

Bild

Call for flash-chips at DEF CON! If you have leftover or rare SPI flash-chips that I can have for testing some tooling I’m building I’d be very thankful. Also if you have devices where you had trouble dumping in-system I’d love to give it a try. I’ll be at Embedded Systems Village :)