DEF CON 32 - Secret Life of  Rogue Device: Lost IT Assets on the Public Marketplace - Matthew Bryant

DEF CON 32 - Secret Life of Rogue Device: Lost IT Assets on the Public Marketplace - Matthew Bryant

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 30:17

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Rogue hardware—such as employee devices, prototypes, and factory equipment—leaks onto secondary markets like eBay and Shu, exposing serious security risks and supply chain vulnerabilities 2:00.

Key Takeaways:
• Employee laptops and prototypes often surface on markets like eBay and Shu, with sellers rarely disclosing the true nature of devices; metadata like "property of Apple" is hidden in images 2:00.
• Image analysis using iPhone-based OCR and barcode detection enables extraction of hidden metadata, with custom tools achieving high accuracy and efficiency at low cost 10:00.
• Research faces technical hurdles on platforms like Shu, requiring reverse engineering, rooted Android devices, and IPv6 proxying to bypass rate limits and encrypted responses 5:20.
• Real-world findings include a 2011 Time Capsule with internal data (support tickets, passport scans, internal memes) and prototype iPhones with debug fuses exploitable for research 16:21.
• Factory equipment with Foxconn labels and drilled holes contains recoverable software and credentials, indicating poor secure destruction practices 24:00.

These leaks reveal systemic failures in hardware lifecycle management and supply chain security, underscoring the need for robust physical protections and secure data erasure.

Sources:

  • 2:00 Overview of rogue hardware and its presence on secondary markets
  • 10:00 Use of iPhone-based OCR and barcode detection for metadata extraction
  • 5:20 Reverse engineering and proxyi

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

good deal thank you all for coming uh this is a secret life of a rogue device um my wife told me not to tell anybody who helped me with these slides and make them look beautiful so I'm just going to say a beautiful Anonymous woman help me make these look nice uh the earlier format was much ugli I assure you so yeah quick background I'm Matthew uh my friends call me mandatory worked on a variety of security projects things like xss Hunter uh curs Chrome and I write security research at the hacker blog.com in my professional life I also lead the red team at snap so this talks sort of about quote unquote Rogue Hardware uh ending up on the secondhand online Electronics markets so what do I mean by Rogue I mean things that shouldn't end up there this is kind of a few key categories right things…