BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.ozsecurity.org//ozsec-2026//talk//8FFRB3
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T080000Z
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T090000Z
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-ozsec-2026-8FFRB3@cfp.ozsecurity.org
DTSTART;TZID=CST:20261023T143000
DTEND;TZID=CST:20261023T151500
DESCRIPTION:Firmware extraction is a critical first step in hardware securi
 ty assessments\, and eMMC storage is one of the most commonly encountered 
 targets across "higher-end" embedded AI and IoT devices. This talk covers 
 two practical approaches to extracting firmware from eMMC chips: in-circui
 t lead tapping and full chip-off removal. We walk through identifying eMMC
  pinouts\, soldering to exposed test points\, and interfacing with afforda
 ble readers for in-circuit extraction\, then cover hot air desoldering\, B
 GA reballing\, and reading bare chips via socket adapters for chip-off. Fo
 r each method\, we discuss tooling\, trade-offs\, failure modes\, and when
  to choose one approach over the other based on board layout\, risk tolera
 nce\, and common obstacles like epoxy potting and locked partitions.
DTSTAMP:20261011T015336Z
LOCATION:Redbud C
SUMMARY:eMMC Firmware Extraction - neko
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/8FFRB3/
END:VEVENT
END:VCALENDAR
