Xeno Kovah
@xenokovah
Interested in reverse engineering, firmware, bluetooth, trusted computing, and training. Founder of OpenSecurityTraining2
Today’s talk with @veronicakovah.bsky.social is basically a dream come true for me! It’s our first joint talk ever and it’s at @defcon.bsky.social 20 years after we got married in Vegas! 😃
. @veronicakovah.bsky.social & my DEFCON abstract now published here: defcon.org/html/defcon-... Waypoint-driven LLM BT RE FTW!
Allow me to join the chorus of “Fable 5 is broke as a joke” Crossposted with @openvibe.social
If you managed to snag a ticket to @districtcon.bsky.social, I hope to see you at my talk on reverse engineering the Realtek RTL8761B* series of Bluetooth chips (where I will once again be trying to irresponsibly speed-run way too many slides)
As VUSec is one of the places that found some of the early "named/logo bugs" for microarchitectural attacks, I liked that they had an emulation cabinet with a "LOGO INVADERS" design on it :)
New life philosophy (x.com/xenokovah/st...) is helping me understand my general anti-CTF sentiment and why I feel like CTFs are a waste of peoples’ lives: “Solve *problems*, not puzzles”. If they’re the same, great. But I’ve seen lots of CTF *puzzles* which don’t teach problem solving.
@districtcon.bsky.social looks like it has a pretty great lineup of talks and speakers this year (districtcon.org). I’ll be there too, talking about my new Realtek Bluetooth chip RE work
🧵For those who are curious about the completion time distribution during the beta of my #OST2 BT2222 class, here it is. The average completion time was 8h25m, the median was 8h10m, the min was 3h50m, and the max was 15h22m
And a new paid 3-day training with @veronicakovah.bsky.social where we take you from the bottom of the stack to the top, to build the next generation of Bluetooth Low Energy hackers! (hardwear.io/netherlands-...) Anticipate many more BT hackers in a couple years, and prepare accordingly ;)
a free workshop (hardwear.io/netherlands-...) (where you get to borrow some of my hardware to get a taste of my free 1-day #OST2 class ost2.fyi/BT2222)…
🧵Alright! I pulled off the hat trick 🎩 at hardwear.io this November! I've got a talk on 100% new firmware reverse engineering research (hardwear.io/netherlands-... tagline:SUFFERING BUILDS STRENGTH!)…
WiFi security researchers: I want to get a TX amp to let my BT research tools connect back to further-away advertisers. I’m considering www.digikey.com/en/products/... . Is there a better option that’s used in the WiFi space that I could be considering?(Needs to work with USB BT dongles)
If elected to the role of Global Supreme Documentation Overlord Czar, I promise a chicken in every pot, and a README.md in every subfolder!
The abuse of the term “ROM” continues unabated… I love how they even spell it out here and still don’t see the problem…
Random trivia: I hadn’t looked at the spec for this before, but apparently BT Classic masks the opposite side of the key relative to BT Low Energy when two parties negotiate a lower-strength encryption key ¯\_(ツ)_/¯
My new talk on reverse engineering the firmware of Realtek RTL8761B Bluetooth chips has been accepted to @hardwear-io.bsky.social in Amsterdam in November. Abstract in image due to size limits.
I’ve uploaded a good chunk of my Blue2thprinting data collected in Sweden at SEC-T to BTIDALPOOL. And in honor of the Meshtastic workshops, I also added some Meshtastic UUIDs to CLUES which takes one from image 1 -> 2/3 (if you pass —verbose-print)