DEF CON 32 - From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller - Stacksmashing

Поделиться
HTML-код
  • Опубликовано: 20 ноя 2024

Комментарии • 207

  • @yoothmag
    @yoothmag Месяц назад +555

    I have absolutely no clue what I'm watching but I'm definitely here for it

    • @akbarudinmajid
      @akbarudinmajid 27 дней назад +14

      Me too 😂😂

    • @Raaa010
      @Raaa010 26 дней назад +3

      Hahaha me the same 😂 but it's fun to watch

    • @carlos11111926
      @carlos11111926 26 дней назад +9

      i'm engeenier and trust me.. i don't know it either xD

    • @TrykyShow
      @TrykyShow 25 дней назад +1

      same here 😁😁

    • @pandaaa8449
      @pandaaa8449 25 дней назад +1

      real

  • @unsaltedskies
    @unsaltedskies Месяц назад +271

    stacksmashing has to be the highlight of any defcon

  • @menno763
    @menno763 Месяц назад +671

    Hardware hacking is so insanely cool, i dont even want to know how many hours this all cost.

    • @akashsxo
      @akashsxo Месяц назад +69

      have you fallen in love with someone? if yes, you don't track the time you spent with them, it's the same, he loves his art

    • @LoveDoveDarling
      @LoveDoveDarling Месяц назад +3

      @@akashsxo Could you explain to me how this is relevant to the original comment? After reading both, I see that the original comment and reply are addressing different things. If you could elaborate, that would be great. Thanks.

    • @barbiani
      @barbiani Месяц назад +1

      So I am not telling you that it probably took all of his hours.

    • @akashsxo
      @akashsxo Месяц назад +1

      @@LoveDoveDarling your name is enough ☺

    • @LoveDoveDarling
      @LoveDoveDarling Месяц назад

      @@akashsxo Enough of what...?

  • @upmoep
    @upmoep Месяц назад +199

    There do be wizards walking among us mere mortals.

    • @xj0ex39
      @xj0ex39 3 дня назад

      #WizardChan

  • @Mark-qt8fs
    @Mark-qt8fs Месяц назад +56

    Never been more fascinated and confused at the same time...

  • @wyron1160
    @wyron1160 3 дня назад +2

    My University professor showed this video to me. It is absolutely fascinating. I feel so confused yet so motivated. Amazing stuff!

  • @doublepinger
    @doublepinger Месяц назад +127

    Voltage fault injection reminds me of some laptops to be re-sold, at work. The BIOS / UEFI was password protected, but they were a "higher-end" model with a "secured boot failure" feature... if the BIOS repeatedly failed to initialize, a re-flash or such would occur. By ever so slightly shorting one of the TX pins to ground while it was booting, it would reboot... to a Factory Initialization message. Haha yeah, one only need to enter the serial number printed on the laptop, and it would then "be that laptop", as well as save a password and then immediately clear it, because otherwise it was still on the flash, recalling. I recovered like 7 or 8 of 10 laptops that way.

    • @BillAnt
      @BillAnt Месяц назад +10

      Those days are over, everything is encrypted now.

    • @huntards
      @huntards Месяц назад +1

      Had to do this with a lot of old chromebooks

    • @dh2032
      @dh2032 Месяц назад

      come you drop a story like that, and not details what laptop model it was and ping shorted out a little (did your a rissistor or something for the shorting a little part? are just paper clip? 🙂

    • @doublepinger
      @doublepinger Месяц назад +4

      @@dh2032 It was a Dell model, but it was over a year go, one of many I worked on. I just had a small metal tool, like a flathead, and I was scraping one side of what I believed to be the bios chip (tiny little 8-pin dip). If I scraped too early it wouldn't boot at all, but there was a certain part of it's LED flashing iirc, I could time it. The fan sounds would be different, and rebooting (without contact?) would boot it into the "Manufacturing" mode.

    • @Noam3k
      @Noam3k Месяц назад +12

      @@doublepinger I have a similar story with one of my previous PC builds.
      PC froze while updating BIOS during first setup, seemed to be fully bricked.
      Looked online, turned out only option is to go ahead with a return. Which would suck as I was just setting up a new build after waiting on the parts for quite a while.
      One user described a similar issue on a different motherboard model, and he was able to short two pins to get the DUALBIOS thing to kick in and un-do the brick.
      The issue was that they had a different mobo, and schematic of the pins from the manual they attached didn't correspond to the chip on my motherboard.
      Had to go to my boards manual, find the chip on my board, look up the model, look up the chips specs, look at the routing of the pins and compare to the chip the other user posted.
      I remember the pins were named differently, so that required some deep diving into the docs to find that XYZ on my boards chips corresponds to ZYX on the other boards chip.
      Once I was sure which of the pins to short, I was like 49% sure it would go up in flames, 49% sure I get electrocuted, and 2% sure it would work.
      Insulated myself from the paperclip I was using, and was shaking quite a bit while trying to only touch the 2 of the 8 pins required lol
      But I went ahead... AND IT WORKED!
      Shorting the 2 pins unbricked the BIOS brick, and I was able to proceed with the updates without any other issues.
      Felt like I'm a wizard & it was amazing that I didn't have to RMA a new motherboard that got bricked during a bios update.
      One of my fave PC troubleshooting stories as a 'normal PC user' / someone not working in the hardware/PC sector.

  • @JonMasters
    @JonMasters Месяц назад +140

    You only have to hear his name to know it’s gonna be an absolute *banger* of a talk

    • @Pokornz
      @Pokornz 28 дней назад +3

      It really did sound like "sexmachine" 😂 Shows the importance of syllable stress (should have been pronounced stacksMAshing instead of stacksmaSHIng)

    • @xj0ex39
      @xj0ex39 3 дня назад

      #Juju

  • @lahtin3n
    @lahtin3n Месяц назад +70

    I just watched 36 minutes of something I have absolutely 0 knowledge or understanding of. This was interesting.

  • @SalzmanSoftware
    @SalzmanSoftware Месяц назад +198

    This just goes to show all the work that goes into the new Jailbreak every year! But seriously, this could allow a new semi-untethered Jailbreak!

    • @DreamBeamz
      @DreamBeamz 26 дней назад +1

      This is amazing honestly. Reminds me of the hacking of DirectV’s HU card in the early 2000’s

    • @MLGPRO-dx8fg
      @MLGPRO-dx8fg 24 дня назад +4

      If you can get to the chip on the iPhone, you could probably get a unpatchable jailbreak
      Idk the extent to how the communication works between the SoC and ACE3 on the iPhone, but if you can compromise it before/during boot, then there's nothing Apple can do about it lol

    • @pietrekk1
      @pietrekk1 19 дней назад +1

      @@MLGPRO-dx8fg this would make me come back to iPhone from android

    • @Abhishek__Parihar
      @Abhishek__Parihar 3 дня назад

      @@MLGPRO-dx8fg has anyone done it on newer ios versions, it's eassy to get to the chip if it's outside of sandwich board might be little tough if it's inside.

  • @N30_W01f
    @N30_W01f 10 дней назад +4

    Wow, amazing talk! And not only do you care about glitching the chip, you take extra steps to see how it could be reproduced with more commonly available hardware instead of expensive professional machines. That's amazing, and awesome for you to do that!

  • @em00k
    @em00k Месяц назад +141

    Persistence is the key! Top work!

  • @mangatmangat6520
    @mangatmangat6520 День назад +1

    This is totally another world technology and skills. Man you are an Alien.

  • @Shamboopy_
    @Shamboopy_ 23 дня назад +6

    What he is talking about and doing is amazing. It’s even more incredible to think that somewhere there is a group of engineers that thought about all of this and incorporated it.

    • @xj0ex39
      @xj0ex39 3 дня назад

      That was one “intelligent” group of field engineers there bruh.

  • @NKCSS
    @NKCSS 27 дней назад +7

    This has to be one of my favorite defcon vids so far. Awesome stuff!

  • @R2_D3
    @R2_D3 28 дней назад +14

    35:45 The; ''And it's not super difficult'' part cracked me up!!! 😂

  • @williambrasky3891
    @williambrasky3891 23 дня назад +8

    This has to take the cake for most impressive presentation at this year’s DEFCON. Granted, it’s the first one I’ve so far seen, but still. It’s got everything, multiple zero-days, responsible disclosure, Apple being jerks, refusal to address disclosed vulnerabilities (we just released a new chip thats not affected. Wanna be secure? Buy the new $3,000 computer), SPITE…engaged, whacky hacky shenanigans, no information, just spite, somehow convert pure spite into actual information, still tho no way this actually works, no fucking way, spite wins, it’s to the buzzer but spite wins somehow, all this, plus what’s got to be one of the most technically impressive h/w hacks of the year. Bravo! Unfortunately, there’s absolutely going to be some serious blowback from all this. I think it just convinced me to buy a Mac. I finally get it. It’s not the aesthetic or some “ecosystem” that draws ppl to Apple. It’s the spite. That’s not a computer. It’s a 3,000 dollar motivation machine. I was blind, but now I see!

  • @Nordkrafts
    @Nordkrafts Месяц назад +13

    So now you can get a 60$ pico instead of a 130$ fancy charging cable. Props.

  • @Crazy1793
    @Crazy1793 Месяц назад +11

    I don't understand nothing but i warched everything and learned something

  • @almc8445
    @almc8445 Месяц назад +39

    Commenting for the algorithm, this is awesome af!

  • @samuelolaegbe2747
    @samuelolaegbe2747 18 дней назад +2

    I know about hardware but this is so cool to watch! Someday I’ll understand all this.

  • @jakobfindlay4136
    @jakobfindlay4136 Месяц назад +8

    Gotta love when someone does it with 8k of equipment then makes it work on 60$ of equipment

  • @jjoonathan7178
    @jjoonathan7178 Месяц назад +25

    Wow! Brilliant and next level persistent!

    • @dogbog99
      @dogbog99 Месяц назад

      Like all good hackers

  • @shapes4893
    @shapes4893 21 день назад

    So far from Defcon 32, this has been the most impressive video of reverse engineering released

  • @YoutubeHandlesAreDumb67
    @YoutubeHandlesAreDumb67 11 дней назад

    Quite interesting. It's crazy seeing Fabian being mentioned everywhere after taking one of his courses.

  • @hahahuhu628
    @hahahuhu628 Месяц назад +11

    i do comments very rarely, one per several years, rofl ... but ... this guy blow my mind ... i like the way he is thinking, excellent problem solving road map imagination

  • @FOM_extras
    @FOM_extras Месяц назад +15

    he deserves literally so much

  • @Office3
    @Office3 Месяц назад +15

    Thanks asahi for the 206

  • @myfaveyoutube
    @myfaveyoutube Месяц назад +6

    The Central Scrutiniser.. first time I've seen a Frank Zappa reference in a hacking tool. Listen to Joe's Garage, it's a great album

  • @KG4JYS
    @KG4JYS Месяц назад +36

    Ouch, $4,000 chipshouter? Glad you did it for us. Using a $4,000 glitcher and then saving money using a hackrf instead of a scope doesn't make a ton of sense to me.

    • @MiesvanderLippe
      @MiesvanderLippe Месяц назад +9

      What do you think a good scope costs? Do you think he paid full price for the other device? Could it be an academic exercise to do it the cheap way?

    • @BillAnt
      @BillAnt Месяц назад +21

      It only takes one researcher to work out the signal, now you can do the same with a $60 PICO board.

    • @fred3965
      @fred3965 Месяц назад +2

      He said he wants to make it more accessible not everyone has that much to spend on specialised hardware

    • @grant-is
      @grant-is Месяц назад +11

      Did you watch to the end?

    • @KGIV
      @KGIV Месяц назад +2

      @@grant-is Of course not. Many such cases.

  • @FelixHartmann
    @FelixHartmann Месяц назад +3

    at least thump up for this efford! congratulations :)

  • @seanys
    @seanys День назад +1

    Meanwhile, I can’t even jailbreak my 10 year old iPad.

  • @Cambeast123
    @Cambeast123 Месяц назад +3

    Cool use of the hackRF!! Love mine

  • @felipecarlin8540
    @felipecarlin8540 Месяц назад +7

    This is just wild.

  • @Dave-McRae
    @Dave-McRae Месяц назад +8

    What a legend! 🎉

  • @FernandoGranco
    @FernandoGranco Месяц назад +8

    Amazing work!

  • @sudo_Ibiza
    @sudo_Ibiza 29 дней назад

    I am proud of you guys!...keep up doing the good work.

  • @alpha_pixel_
    @alpha_pixel_ Месяц назад +14

    Apple security left the chat

  • @Raymond23rdOBC
    @Raymond23rdOBC 27 дней назад +1

    apple engineers taking notes

  • @Einimas
    @Einimas 29 дней назад +2

    I once tried to reverse engineer a smart fridge, but in the proces a jtag grew on the back of my head.

  • @alexcrouse
    @alexcrouse 29 дней назад

    This is incredible. Fantastic work!

  • @Neo_AIO
    @Neo_AIO Месяц назад +8

    Louis Rossmann needs to hire this guy😆

  • @BHBalast
    @BHBalast Месяц назад +3

    Impressive, just impressive!

  • @m.i.b7689
    @m.i.b7689 11 дней назад +1

    Apple are really something they designed everything very well also protected it with almost no vulnerabilities grt. I thought making a laptop would b easy just put parts but no they hv put some serious work in it🎉

  • @procrvstinvtion8479
    @procrvstinvtion8479 16 дней назад

    This is insane. Very impressive

  • @ali2naveed
    @ali2naveed 7 дней назад

    i had a dream to become a hacker and by watching this guy motivated me to quite.

  • @NeverGiveUpYo
    @NeverGiveUpYo Месяц назад +3

    Amazing talk.

  • @sk3tchimdg3t33
    @sk3tchimdg3t33 Месяц назад +2

    it's impressive like super impressive

  • @silentninjabee2985
    @silentninjabee2985 29 дней назад

    Thank you for your World Champion open sourcing effort! I hope you did all this research and got the MacBook refunded 😂

  • @howardalien2720
    @howardalien2720 Месяц назад +5

    But can he center a div?🤔

    • @xanderplayz3446
      @xanderplayz3446 29 дней назад +1

      But can he make a div slide from the right to the left of the screen and loop?

  • @crlfff
    @crlfff 29 дней назад +1

    Absolutely insane

  • @mactalk2871
    @mactalk2871 Месяц назад +1

    brilliant work!

  • @weirdmeisterinc
    @weirdmeisterinc 27 дней назад +1

    great insights

  • @erentr7167
    @erentr7167 Месяц назад +9

    craziest shit ive ever seen

  • @urban6989
    @urban6989 Месяц назад +1

    awesome stuff!

  • @mfThump
    @mfThump 29 дней назад

    23:57 an apt description of tech companies

  • @martinshreder
    @martinshreder Месяц назад +2

    Impressive

  • @Hasan_OZ
    @Hasan_OZ 21 день назад +1

    I’m from Turkey and if you want to buy an iphone you have to pay 3000$ dollars, 1k for the phone and other 2k for the government, and i wish this guy can create a tool to change the imei number on the phone so i can use phones bought from abroad 😂

    • @Wierie_
      @Wierie_ 10 дней назад

      The grass might seem greener but at the end of the day its an overpriced phone with decent build quality that runs the same apps

  • @Fosgen
    @Fosgen 3 дня назад

    Excellence.

  • @harveyweizman
    @harveyweizman 18 дней назад +1

    Basically what he’s saying is don’t buy Apple products…

  • @downthecrop
    @downthecrop Месяц назад +3

    Badass

  • @gercekbko
    @gercekbko Месяц назад +1

    So cool.

  • @lovro1423
    @lovro1423 Месяц назад

    Amazing 🔥

  • @dr-deep8353
    @dr-deep8353 Месяц назад +1

    Music is good

  • @kritikusi-666
    @kritikusi-666 Месяц назад +5

    what a smart cookie. The zapping works on kids also. They start behaving. No questions. jk (obviously).

  • @zeromant80
    @zeromant80 29 дней назад

    Amazing!

  • @GridPB
    @GridPB Месяц назад +1

    The presentation is clearly not a Powerpoint, what is it made in?

    • @devnol
      @devnol 27 дней назад +1

      Apple Keynote has some really slick templates you can build upon, it might be one of those. iWork is actually pretty darn good.

  • @ClosetFemboy
    @ClosetFemboy Месяц назад +2

    Based

  • @ja.935g67
    @ja.935g67 25 дней назад +1

    Hello this is Tim Cook I would like to know where you live 🤣

  • @DMack6464
    @DMack6464 Месяц назад

    Do all these need auth or are these pwn methods as well?

  • @zxljmvvmmf3024
    @zxljmvvmmf3024 Месяц назад +3

    lit

  • @sladeoss
    @sladeoss 21 день назад +1

    What a fucking legend

  • @kbwinter
    @kbwinter 24 дня назад

    It already comes loaded with a back door…you just don’t know it yet…😢

  • @mojoblues66
    @mojoblues66 5 дней назад

    12:33 Apple probably doesn't consider this a security issue because it requires SIP to be disabled.

  • @arnaudj2708
    @arnaudj2708 Месяц назад +1

    35:29 dumping unknown silicon is not super difficult
    Hmmm... I disagree

  • @ronbaer67
    @ronbaer67 27 дней назад

    so does this mean jailbroke iphones are back on the menu?

    • @SamSayaz
      @SamSayaz 19 дней назад

      I am curious too. And don't understand the full effects of this research

  • @swagteck8925
    @swagteck8925 Месяц назад

    This is awesome!

  • @bzmgames1308
    @bzmgames1308 2 дня назад

  • @geteilt
    @geteilt 27 дней назад

    He keeps saying „you know“ but I actually have no clue. Does the audience also just.. you know… know?

  • @eLab43
    @eLab43 Месяц назад +1

    In newer iPad Pros, air, and MacBooks, the CD chip is paired to the small ROM chip.
    If I need to replace the CD chip because it turned out to be bad, I cannot install a new one. I need to pull a pair of cd + rom from another donnor motherboard.
    Do anyone have an idea how to re write the rom chip to the new CD?

    • @bagotaitamas
      @bagotaitamas 14 дней назад

      Eeprom programmer, either spi or i2c. But if it has the security measures like this (ACE3), a simple reprogram won't be enough. Basically you need to glitch like in the video, get past security, dump and patch internal flash to accept other CRC. I'm sure it's currently out of your reach. Also not too fast or reliable on one chip, not to talk about shops that replace multiple a day.
      Your easiest option is to replace CD, and flash its own rom, but reading/writing takes longer than swapping it out too.

    • @eLab43
      @eLab43 14 дней назад

      @ thanks you!!

  • @myusuuf
    @myusuuf 18 дней назад

    Stacksmashing sounds like sexmachine at first

  • @hashfors
    @hashfors 25 дней назад +1

    Forced to use usb-c eyyy..

  • @ViniciusMiguel1988
    @ViniciusMiguel1988 Месяц назад

    Louis Rossmann would like to know this

  • @schwellhaimbassriot2660
    @schwellhaimbassriot2660 Месяц назад

    maestro

  • @SickHedgehog777
    @SickHedgehog777 28 дней назад

    60$? shouldve said 59.99 and weaved in some cool words like Jobs used to do :D

  • @nd.c.1098
    @nd.c.1098 15 дней назад

    I only understands the first 5 mins...haha

  • @computer_carnivore
    @computer_carnivore 26 дней назад

    Ultra 1, I’m bugging

  • @bloxycola8272
    @bloxycola8272 28 дней назад

    I wanna learn hardware hacking

  • @p4rk5h
    @p4rk5h Месяц назад +1

    So basically they followed the Qualcomm way of entering Recovery (which uses Qualcomm QuickCharge negotiation process)

  • @ErCapoAlex
    @ErCapoAlex 15 дней назад

  • @ramnikTDM
    @ramnikTDM 13 дней назад

    daymn

  • @imranexltd
    @imranexltd 17 дней назад

    Ye was right. 😢

  • @pabloalonso9083
    @pabloalonso9083 24 дня назад +1

    Is this even legal ?

    • @almostprofessionalrecords6651
      @almostprofessionalrecords6651 23 дня назад +1

      In Europe, yes.

    • @jani0077
      @jani0077 23 дня назад

      in the EU, until you use it for commercial purposes, yes. (He's not selling reverse engineered products from the firmware dumps, at least I'm not aware)

  • @DontTrip-lu5hm
    @DontTrip-lu5hm Месяц назад +1

    🎉

  • @carl2k6
    @carl2k6 Месяц назад

    Like #1337. that my level. His: another planet

  • @SpenceReam
    @SpenceReam Месяц назад +2

    RSA3072… 😂

  • @vadim2639
    @vadim2639 Месяц назад

    Is that usb device that border control uses to scan your entire phone?

  • @NickIlVento
    @NickIlVento Месяц назад

    WOW

  • @codefor69
    @codefor69 25 дней назад

    Wow this is so frigtned

  • @nickjeffrey8050
    @nickjeffrey8050 Месяц назад

    Anyone boasting about a jailbreak on iphome 15 means nothing anymore 🤣🤣🤣