I'm Isaiah, a hardware security researcher with six years of experience breaking things for fun and occasionally for work. I specialize in tearing apart white-labeled IoT devices, firmware extraction, and lock picking/bypassing. When I'm not desoldering eMMC chips or tracing wires, I'm writing Bash scripts that probably shouldn't exist and automating things in ways no one asked for. I also love cats. You can find me as codeneko or netcode in most places.


Sessions

10-23
10:00
45min
Sneaking Malicious Hardware into a Keyboard
neko

Rubber Ducky's are pretty well known so you might hope a user won't just plug in a random parking lot flash drive, but do you think they might plug in a random keyboard that looks exactly like the keyboard they already have? Especially if they are told it is a magical keyboard that will make their computer much faster?

This talk is all about designing and building a malicious keyboard and then what you can do with it and how you might go about defending from something like this.

Redbud A
10-23
14:30
45min
eMMC Firmware Extraction
neko

Firmware extraction is a critical first step in hardware security assessments, and eMMC storage is one of the most commonly encountered targets across "higher-end" embedded AI and IoT devices. This talk covers two practical approaches to extracting firmware from eMMC chips: in-circuit lead tapping and full chip-off removal. We walk through identifying eMMC pinouts, soldering to exposed test points, and interfacing with affordable readers for in-circuit extraction, then cover hot air desoldering, BGA reballing, and reading bare chips via socket adapters for chip-off. For each method, we discuss tooling, trade-offs, failure modes, and when to choose one approach over the other based on board layout, risk tolerance, and common obstacles like epoxy potting and locked partitions.

Redbud C