#418 – An Interview with Josh Datko

Download episode · 75 MB
Also on Apple · Spotify · YouTube · RSS
Show Notes
Welcome, Josh Datko!
- Chris and Josh met at Black Hat this past year while Josh was helping former guest Joe Fitzpatrick give a training and Chris was "helping" past guest Colin O'Flynn give a training.
- 0h 1m 2s
- Josh attended the US Naval Academy
- 0h 1m 24s
- 5 years in a sub, recalled to go to Afghanistan
- 0h 2m 10s
- Josh was a Trident scholar
- 0h 3m 50s
- Operational Security (opsec)
- 0h 4m 34s
- Naval academy students all graduate as engineers
- 0h 5m 12s
- Nuclear power school
- 0h 8m 45s
- Submarine reactor system
- 0h 10m 45s
- Primary and secondary loops
- 0h 10m 59s
- Los Angeles class submarine
- 0h 13m 24s
- The sub he was on was an independent operations boat
- 0h 14m 35s
- List of stories was vetted by his wife
- 0h 15m 55s
- "The military is not like real life"
- 0h 18m 3s
- Cloud story
- 0h 18m 56s
- IRC story
- 0h 22m 19s
- Dog and cat story
- 0h 26m 40s
- Practical cryptography
- 0h 30m 57s
- Going to work for a defense contractor
- 0h 33m 34s
- Very process oriented, lots of GANTT charts
- 0h 34m 23s
- Went back to grad school at Drexel
- 0h 36m 47s
- Tor is a network on a network - overlay
- 0h 37m 14s
- Security and privacy lab at drexel
- 0h 40m 17s
- Talk at DEFCON25 about glitching the trezor
- 0h 43m 51s
- Josh will be giving a talk with Thomas and Dmitry at 35c3
- 0h 47m 45s
- Symettric vs asymettric vs elliptical cryptography
- 0h 49m 29s
- Dmitry on the show
- 0h 52m 57s
- Supermicro servers
- 0h 53m 59s
- Backscatter on a VGA cable
- 0h 56m 37s
- Chuckwagon
- 0h 56m 50s
- Best practices for embedded security
- 1h 4m 32s
- Threat modeling
- 1h 4m 41s
- Formalizing the process of security
- 1h 7m 20s
- Blockchain hackathon in Wyoming
- 1h 15m 31s
- Beefchain
- 1h 18m 40s
- Story about Afghanistan
- 1h 20m 25s
- JCREW
- 1h 23m 44s
- Cryptotronix.com
- 1h 29m 17s
- wallet.fail
- 1h 29m 35s
- Josh can be found as @cryptotx on Twitter
- 1h 29m 55s
Transcript
Josh Datko: This is The Amp Hour Podcast. Released December 2nd, 2018. Episode 418. An interview with Josh Datko.
Chris Gammell: Welcome to The Amp Hour. I'm Chris Gammell of Contextual Electronics. And I'm Josh Datko from Cryptotronics. Welcome, Josh. How are you doing? Doing well, Chris. Just put up a Christmas tree. Things are going well.
Josh Datko: All right. Tis the season. Yeah. Things are moving along. It'll be 2019 before we know it. Yeah. It's crazy. So what is Cryptotronics and what's your background? Maybe we should start with how we met and then we can kind of go back.
Dave Jones: Oh, yeah. Yeah. Well, we met. I think we met at Black Hat this year. Yeah. Yeah. To go back. So I own a company called Cryptotronics. It's a consulting contracting security, mainly embedded security company. I'm the owner. We have four employees. Been doing it for five years. We had our five-year anniversary just like a week ago. Wow. Congrats. Yeah. Before that, I graduated at U.S. Naval Academy. So I started off thinking I was going to be a career naval officer. Did that. Was in a submarine for about five years. Left the submarine. Worked for a defense contractor, making little black boxes for the government. Then I was in the reserve. So I got recalled to go to Afghanistan to help the army because apparently the army needs the base help.
Josh Datko: I was going to say a lot of subs in the desert there.
Dave Jones: Yeah, exactly. Well, so my joke is that I did my mission. The Taliban has not yet developed a submarine force. So I can claim mission accomplished. That's right. That's right. Yeah. So I don't know.
Josh Datko: That's a healthy slogan to use. It's not been overused anywhere else.
Dave Jones: Right, right. Yeah. It has no negative connotations. Yeah. So I was recalled to go to Afghanistan. That was kind of interesting. And then I got out for good. So that was kind of like, I'm not doing that again. And moved to Colorado where I live now. And then, yeah, started this, started Cryptotronics. So, yeah. So then we met at Black Hat. And I have helped Joe Fitzpatrick, who has been on your show before, I think. And with his hardware hacking class. And I can't remember why you were there. But somehow we ran into each other. And I recognized your voice. Yeah. Yeah.
Josh Datko: Yeah. Yeah. I was helping Colin with his class. Helping is a, you know, in quote marks. But, yeah. Yeah. Similar. I think you actually are able to help Joe. I was just kind of observing Colin. Oh, yeah. So. Well, sometimes I just.
Dave Jones: Past guests of the show. Oh, yeah. Right, right. Yeah. Yeah. So those guys are great. Yeah. So I. Yeah. I. My goal in helping Joe is to not have him get any negative comments on behalf of me. Right. Right.
Josh Datko: So the reviews and everything.
Dave Jones: Exactly.
Josh Datko: Yeah. Yeah. Yeah. So. Okay. So first off, you're our first military guest. And that's super cool, actually. Yeah. After 400 some shows. So I would love to hear more about that kind of stuff, too. But. But because of the leap. The leap to embedded and security. It seems odd to me. But I'm guessing that's somewhere in the black box thing that you'll get to. Yeah. I.
Dave Jones: I had kind of a. Yeah. It's kind of an interesting path to get here. So. So. Yeah. So in the Naval Academy, I. I was kind of like really book smart more than any other kind of smart. So I ended up doing pretty well. I graduated like 45th in the class of 900 something. And then did a lot of. Yeah. So I did that. So I was able to do this program called Trident Scholar, which allows you to spend the last year kind of doing undergraduate research of which I did kind of cryptography and more like application of cryptography. That's cool. Aircraft. Yeah. The paper is embarrassing to read now, but it was fun.
Josh Datko: So I kind of like. I mean, military stuff has a lot of, you know, like a lot of the cryptography stuff's interesting. And I think the Internet is one main thing, but I think military is a huge consumer of military intelligence. All those communities are consumers of the, you know, the high security type of, you know, understanding what cryptography and everything like that.
Dave Jones: Yeah. Especially from a operational perspective. So there's a lot of, you know, the, you know, the term is OPSEC in operational security. So there's a lot of that, you know, as a operator in the military, you don't necessarily get into, go into some of the details. I mean, now, now if I would have gone back, I would be way more geeking out into like, oh, let me, let me open that thing. Let's see the circuit board, which is generally bad to do. Yeah. I don't like it. Yeah. But yeah. So, so that's a kind of got the start in, but so I was a computer science undergrad, but I had an interest in security then. So the Naval Academy, you, even if you're an English major, you graduate an engineer. So even English majors. Yeah. Even English majors are taking circuits like circuits 101. And so you can't, you can't graduate without actually having some electrical engineering, some thermodynamics, some mechanical engineering, some weapon system engineering. Everybody has to take this. So computer science is considered a group two. It's in the middle. It's not like electrical engineering, but it's not, you know, history. So, so yeah, so I took, you know, two semesters electrical engineering, weapon systems class, and then I went into submarines. So submarines, you have five choices at the Naval Academy. Basically, you can go into Navy surface, such as surface ships, the kind of traditional Navy submarines. You can become a Navy pilot. And then the Navy actually essentially has operational control of the Marine Corps. So the other two options are Marine Corps air and Marine Corps ground. Interesting. So yeah, I had no interest in being a Marine. So that kind of eliminated those. The pilot option is a commitment of like 10 years after you get your wings. So you're looking at a minimum commitment of 12 years in the military. So I was like, oh, you know, it's kind of long. The surface ships, I, you do these tours. So like, you know, in your kind of summers at the Naval Academy, you have this like internship job and you go to other parts of the Navy. So I went to the server ship down in Florida is being decommissioned. And it was just like, I can't do this. It was just like, just look around. Like I get it. So I went to a, you know, I did a submarine. So you go, you know, go on a submarine. And like the first thing they do is they put you in charge of driving. So the basically the submarine is basically a plane under the water. It has planes that kind of control how it's moving under the water. And the most junior people in a submarine are the ones who physically have control over those planes. So my first day on a submarine, they put me, they're like here. Yeah. Right. Lost the covenant. So they're like the first day on a submarine. They're like, you know, I'm, I don't know, 19 years old. They're like, Hey, sit on here. You're actually going to be driving the sub. Oh my God. Don't, don't worry. We're right behind you. I'm like, oh, okay. And so, you know, we start to dive, you know, so there's a whole diving procedure. You have to, you know, close all the hatches and all this. It's a big procedure. But when you start diving.
Josh Datko: You're above the surface. Yeah. We're above the surface. Exactly. Okay. Yeah.
Dave Jones: So the submarine, when it's on the surface, you know, just a small, like the whole draft. So the draft is like how deep the sub goes is like 30 something feet, but you only see maybe the first like 10, like when it's on the surface, most of the sub is actually underwater, even on the surface.
Josh Datko: Right. Like an iceberg kind of, right?
Dave Jones: Exactly. Exactly. So, so the first time, you know, my first experience on a submarine, I'm on those planes. We start the dive. And so I, you know, you push down on the diving planes as, and the submarine starts to go down. Well, water starts coming in. Like I start getting wet. Right. And I'm like, okay, this, I mean, I saw some movies before and I'm like generally water in the sub is a bad thing. And I'm kind of like looking around to see how other people are reacting. Cause I'm like, I don't know. I don't want to be the guy flipping out. This is just normal. And, uh, and then I felt a lot better when everyone's like, quick, get the paper towels. And so I was like, okay, it's, this is, this must be minor. Okay. But yeah, that was my, so obviously after that, I was like, yeah, this is what I want to do.
Josh Datko: Oh man. That's great. Right.
Dave Jones: Yeah. Yeah. That's amazing.
Josh Datko: The first day they just put you right in. I mean, like that's a.
Dave Jones: Yeah. It, uh, yeah. So yeah, you just really jump right into it. So, but the other thing that's unique about going subs is that you spend the first year after graduation, basically going to graduate school, you know, for a nuclear power. So all officers on a submarine with the exception of the supply officer has gone through new power school. So what that means is you do, uh, six months of power school down in Charleston, South Carolina. And, uh, it's like six hours of classroom instruction per day. And again, you take another, uh, electrical engineering classes. You take more thermodynamics, chemistry, nuclear physics.
Josh Datko: Like you take thermodynamics with, with big implications.
Dave Jones: Yes. Yeah. Yeah. So, and it's like, uh, it's kind of like a military instruction. So like, you know, they have these, you, if you get like less than, I don't know, like your GPA is very closely monitored. And if you get less than like a three O you have to stay there longer and study. And, uh, it's just, it's pretty painful. Yeah. And then, so you do, yeah, six months of schooling. And then you do six months of operating on a prototype reactor, uh, which is like, like a simulator almost. No, it's a real, it's a real, there's one in Charleston and there's one in Connecticut in New York. And these are like real reactors. They let trainees just operate. And, uh, where does the power output go though? I mean, like, is it just driving a turbine or something? Yeah. Yeah. It's just going, I mean, it's going nowhere. I mean, it's essentially, I mean, it's not, they're not moving. The one in, um, Charleston is actually an old submarine that was converted. I can't remember the type. Schenectady is like a different, I didn't, so I went to Charleston, uh, the Schenectady reactor is kind of like a test reactor. And so it's basically like a dummy load. Um, okay. All right. Yeah. Yeah. But, uh, you do that for six months and then you go to your sub and then you do that all over again. So, yeah.
Josh Datko: Well, and real quick, what do you actually, so like on a, on a test unit like that, what is it mostly about like, so maybe you could give a brief reminder about what nuclear power, what you're really doing there for me and others. Yeah. Yeah.
Dave Jones: No worries.
Josh Datko: Yeah.
Dave Jones: Basically you're boiling water.
Josh Datko: My stuff's like based on like Bond movies and like, maybe like Hunt for Red October. And do they, were those diesel subs or were those actually?
Dave Jones: No, those are, those are nukes. Yeah. Yeah. Yeah. Okay. Um, Yeah. Yeah. So that's, that's cool. Um, yeah. So basically you're boiling water is the kind of, is the whole point. So the submarine reactor system really at a high level, there's two main loops. There's a primary loop. And so there is water that is going through the reactor. Um, and it goes through these main cooling pumps and this primary loop is a closed loop. And then it is connected to a secondary loop, uh, which is a non radioactive water. And it, the heat transfer occurs in the steam generators. Uh, so the primary goes through a steam generator, basically heats up the secondary loop. And that secondary loop is now, uh, steam. And then the steam can drive the turbines, uh, which provide power and, uh, propulsion.
Josh Datko: Um, so it's almost like an HVAC system as well, where you're basically heating. Well, I guess a boiler is like that, right? Where you're, you usually have a heat exchange. You don't necessarily send all the, boilers actually send water all the way through like, uh, radiators. I don't actually know.
Dave Jones: Yeah, I can't. Uh, so I, so if you went to the surface Navy, you would have a boiler. And so I can't, uh, I mean, it's been now I've been out for like 10 years. So some of this stuff is painful. Got it. Okay. Regressed memories. Yeah. Yeah. Yeah. Okay. Um, but yeah, so that's, so basically, so basically the idea is you're, you're trying to, the primary reactors boiling water, uh, in the, in the primary coolant and then transferring it to the secondary, uh, plant where it can, you know, provide propulsion and electricity and all this stuff. So that's, that's the kind of basic idea. Yeah. Okay.
Josh Datko: And so like, yeah, so you were studying the electronic side of things as well. Right. I mean, I understand you know everything, but.
Dave Jones: Yeah. So it was like, so, so mainly my background there, it was, is kind of like power EE, you know, if you were like going to, uh, so that was computer science. Delta NY. Yeah. Right. There's these, yeah, exactly. So, so the electronics, yeah. So the electronics comes in, in the instrumentation and control systems, which I had always kind of like, you know, did well in that kind of, uh, like area of study. So I kind of, I just kind of like that stuff. Um, and so there is, you know, where that comes into play is the like rod control system. Uh, and some of the sensors, you know, have basically, they're basically industrial kind of like industrial, uh, control systems. Yeah.
Josh Datko: Yeah. Yeah. Cool. Um, wow. So, yeah. And what kind of power levels are we talking here too? Cause that's what always boggles my mind.
Dave Jones: Oh yeah. So I'd have to go back and look it up, but I mean, it's like, you know, megawatts and you know, it's, it's got a couple of zeros associated to it. Yeah. Right.
Josh Datko: So it's such a tight package and you're, I mean, those things can just go for like months and months and months underwater. It's amazing. Like they're amazing.
Dave Jones: Yeah. Right. So like you can, I mean, the only thing you're limited to is basically food. So the submarine, you know, has a, has a reactor. So it's the scent. I mean, I think every 30 years I was in Los Angeles class, I think every 30 years, the older ones had to get refueled. Um, so, I mean, if you've got, you've got fuel for 30 years, I can make your own oxygen. Yeah. Uh, you make your own oxygen with the oxygen generator. So we, it brings in water and just splits, um, hydrogen and oxygen. Uh, you can also suck in air, uh, through, uh, like a low pressure blower or via snorkel mast. Uh, so we, so we can get air.
Josh Datko: Oh, okay. Like near the surface, but not necessarily. Exactly. Yeah. All the way up. You're saying. Okay.
Dave Jones: Yep. You, you go close and then you can raise masts and antennas and, uh, like a periscope or, or the snorkel mast or, you know, some other mess. Wow.
Josh Datko: So that's, it's like a spaceship almost, you know? Yeah.
Dave Jones: Yeah. Pretty close. It, uh, I mean, so the longest I was underwater, I think was about six weeks. It was, we, we did a around the world deployment. Yeah. Uh, we left Connecticut, uh, went through the Mediterranean, went through the Suez canal to India. Uh, then we did Japan and then we went to Hawaii and then we went through the and then we went through the Panama canal back through the Caribbean, uh, back home to Connecticut. Holy crap.
Josh Datko: Yeah. Okay. So, and I'm sure that there's some sensitive stuff here. So, you know, feel free to just leave out whatever's not allowed to be said. Yeah. Yeah. But like, how much of the time do people know you're there? I, I guess I don't quite. Oh yeah.
Dave Jones: So there's like, uh, I mean, uh, so there's, yeah. So we were an independent operations boat. So we kind of did our own, uh, special things. And, uh, they are, uh, I mean, people, I would say generally know where you are. Like, you know, obviously the Navy knows like, Oh, Hey, there's a, there's a, there's a thing over there, but like the exact, yeah. I, you know, they don't have the, I mean, there's not like a GPS tracker. Right. Right. Right.
Josh Datko: You're not like the AIS system. You're not like transmitting a beacon and saying, here I am.
Dave Jones: Yeah. So, so that, yeah. So AIS, I mean, so you can receive AIS, um, and it's kind of, uh, and you can transmit, although the Navy generally doesn't. In fact, last year there were two, uh, collisions in the, uh, like Pacific area where there were two surface ships and, uh, you can actually see, you can go back and watch the AIS data and see the collision. And, um, yeah, so it's, yeah, it's so, yeah. So, I mean, yeah, I mean, I remember using AIS, uh, on the sub.
Josh Datko: Cool. Okay. Man. So, so then what did, what did this, how did you not go crazy after six weeks underwater? I mean, like it's super tight quarters, right? I don't know. We're not talking about electronics yet. I feel like I should prompt people. Like I'm so interested in the other stories here that like electronics, we're going to get there, but like, yeah, stuff.
Dave Jones: No, I have, yeah, yeah, no, I have, I have a list. So I was, you know, I had to, I had to go through my wife and make this list of stories. Some of them are, are electronics related. So I tried to, uh, I tried to make some good, some good ones here, but, uh, yeah, I mean, I think I, I had a pretty comfortable, uh, living space. I mean, my feet in my head touched in my bed and, uh, you know, uh, I'm six, three and I could, I could not eat on my side.
Chris Gammell: And they, they touched, they touched the bunk walls. Not they didn't touch. Yeah. It was kind of like a folded in half.
Dave Jones: No, it wasn't folded in half. I mean, it's, it's the equivalent of sleeping in a coffin. So like, so, uh, so, uh, so I was an officer and I eventually had one of the state rooms, which is, uh, you know, quite a big room. And so, you know, just describe how big it is. So you, you open the door and you take one step and you're, you know, you could take one step and then you're at a desk and you take another step and you're at three beds. I mean, so that's quite a lot of room really. I mean, you could fit so much stuff in there. So much. Yeah.
Josh Datko: Yeah.
Dave Jones: And, uh, yeah. Sounds like my college dorm. Yeah, exactly. So, um, so, so that's actually quite a comfortable living arrangement because some of the junior enlisted, they actually have to sleep on top of the torpedoes. And, uh, there's, yeah, there's not enough. So there's not enough beds for, there's like 120 people on a Los Angeles class. And, uh, so there's this term called hot racking. So a rack is a Navy bed and, uh, you know, it's, uh, three people for two beds. So, you know, one guy gets out and the other guy, you know, just kind of rotate. Um, and, uh, hygiene problems get treated very quickly. Self-corrected. It's a very tight feedback loop.
Josh Datko: I hear you guys use those sleeping sacks too, that like everybody has their own like sheets, but it's not like, yeah.
Dave Jones: Yeah. Well, there's like, yeah, well, uh, yes, you can, you, so yeah, the enlisted, I think, right. You can just tear off the sheets and put the other one. I mean, it is an actual bed. You're not like sleeping on top of the like actual torpedo. I mean, you, you, you are literally on top of the torpedo, but there is like an actual bed there. Wow. Um, so when you do, uh, yeah. So when you do, the problem is when you do weapons evolutions, where you have to move torpedoes around, uh, like if your bed is over there, you just like, don't sleep.
Chris Gammell: So, okay. Yeah. Yeah. It's crazy. So, all right.
Dave Jones: So let's hear some of these stories.
Josh Datko: Let's hear some of these stories.
Dave Jones: Oh yeah. Okay. Well, I mean, so, you know, so the thing is like the military is like kind of not like real life. So like you are in it and it's just these crazy situations. And if you, I mean, at some point I realized, and I just kind of step back and I'm just like this, like, this is not real. Like there's, there's so much, like you have to really get in the head mindset of just like, I need to do this job. I'm doing this. Like nothing makes sense, but I need to do this. And I think that's like a problem for me. Like I, I, I would think like, I actually didn't follow orders. Well, uh, which I think is why I ended up leaving the military, but like some of these, I would just find myself in crazy things. So like one of the, um, uh, so like, uh, and then there's some things I didn't like, you know, I just went into. So, you know, when you're doing a sub thing and you're on the periscope, uh, you're supposed to like do this weather observation. So, you know, the, you know, you can imagine a sub out there doing its thing and, uh, you know, we're tracking where the submarines at and all this stuff and you're on a periscope. And so the, you know, basically the way the periscope works is it's just, you know, optical mirrors that bring in light and just kind of like you would think, you know, as you probably are imagining a periscope. So one of the things, uh, the officer does is he's up there and, uh, you do a weather observation and you say like, Hey, the sea state is this. I think the, I think the waves are this high, um, et cetera, et cetera. Well, one of the things you were supposed to, I was supposed to learn was all these different cloud types. So, you know, there's like, and there's a lot of, I mean, if you Google like how many cloud types there, there's lots of clouds.
Josh Datko: Cumulonimbo.
Dave Jones: Yeah. Vernicular. Right. So I knew one, which was cumulus. And, uh, and I think, I think eventually I learned stradonimbus, uh, which are like the hot, so cumulus are the big puffy ones and stradonimbus are these like thin ones. And so I would get on the periscope and then they'd be like, you know, you know, you know, Lieutenant Datko weather observation. And I'd be like, God, man, I don't, I don't know my clouds. And so I would, uh, you know, I would look at the clouds and be like, ah, uh, cloud type cumulus. And so the periscope, um, there's like a video. Yeah. Every time we'd just be like, ah, you know, cause like you're trying to do all these other things. Like you are, you, when you, when you're the officer of the deck, you're like driving the submarine only with your voice. So you're looking, you're the only person looking at the sub and you're trying to keep like all these kinds, you're trying to do a lot in your head. And like the last thing I'm really worried about was what the clouds look like. So, um, but anyway, so like the, so like the captain and everything would be like, you know, Lieutenant Datko, that is clearly not a cumulus cloud. You know, you could start, start getting berated. And I'm like, ah, man, this sucks. I don't know. I don't know cloud. So, so, but I figured out a trick. So, so like I was saying, the light is coming through the periscope and then it gets sent to these, uh, basically cameras. Well, what you could do, uh, is I, on the periscope, I could turn off all the cameras. And the reason I would want to do that is that I would get more light to my eyeball. Right.
Josh Datko: Cause some of the light is bad. Bad eyes. You gotta, you gotta do exactly. Right. Yeah.
Dave Jones: So, uh, so, so, so I would go up there and they're like, oh, you know, so everyone would be snickering. They're like, oh man, here comes Lieutenant Datko. We're going to make him do a weather observation. He's going to yell that. And so I was like, okay, I got this. Right. And, uh, you know, they're like, oh, Lieutenant Datko request a weather observation. I'm like, okay, here he's, here we go. So I would do the waves and all that stuff. And then I would like, I would say turning off the cameras, uh, for better. Like, so I could see better basically. I can't remember what I said, but something like that. And then I would say cumulus. Right. And then everyone was like, whoa, why'd you, why'd you turn off the cameras? Like, you can't, you can't do that. I'm like, no, I, you know, safety of ship. I can't see, you know?
Josh Datko: Yeah.
Dave Jones: And, uh, gotta, gotta, gotta get that light, man. Right. So then this other guy would come on after me and he'd be like, no, no, clearly they're like strato and imbus. And I'm like, well, when I looked at it, they were cumulus. So clearly, but what, and so, so anyway, so then people, yeah, they did change fast. So, so I would always do things like this. Um, got it. Another, so this, so I was this, uh, so I was this. So I was also the radio officer. So this is kind of where I got some involvement in electronics. I was the, you know, radio and, and, uh, uh, crypto officer. So help manage all the crypto on the, on the sub and all the radio communication. Well, one of the thing, um, you know, the sub would do is we'd make these IP radio, uh, networks. So we'd have like IRC. And in fact, we use like.
Josh Datko: Within the sub or. Yeah.
Dave Jones: You'd be on a, on a, on a connection, uh, you know, over, or subtly. And then you'd be able to get to a, it's just like a, you know, normal internet. Um, you know, but it'd be the military version of the, of the internet. Uh, but you would use, you would be using IRC, which is like we'd Merck like MIRC. Right. Right. Right. Right. Yeah. And so Merck had this thing. And it's just like, just like, this is a, so this is, we're using this on a submarine. It's just a completely like civilian, uh, you know, like, you know, freeware program. Yeah. Right. And, uh, yeah. And you had this button where if you right click someone's name, uh, you could like, it did this macro and it would say slaps with a big brown trout.
Chris Gammell: Oh yeah.
Dave Jones: And yeah. Right. So, so, uh, so one day I was the radio. Yeah. So I was the radio officer. And one day, you know, we're like talking to our squadron who's like the, like basically in charge of the, of the, uh, like four or five subs. And one of the radio guys like accidentally hits this button and it says, you know, like radio guy slaps squadron officer with the big brown trout, like in the chat. And so I get called, you know, I get called to the captain's, uh, stay room and you know, he is a, you know, this was, uh, you know, a few years ago. And then these guys, some of these older guys didn't really get computers as well. So he's like, you know, Hey, Lieutenant Adco, why are you guys slapping people with big brown trouts? And I'm like, no, sir. Like he didn't actually, he didn't type. He's not actually slapping them with a trout. He like, right. He's not taking time to probably type that all out.
Chris Gammell: Right.
Dave Jones: Right. Like he didn't, he's like, you know, you know, you, you, you know how bad this makes us look if he goes around.
Chris Gammell: And I'm like, sir, he didn't, but he didn't, you know, it was like a button. Encrypted military operations. Right. Lieutenant. Oh my God.
Dave Jones: Yeah. So I had to like, and so the other time, uh, so we're going to have to like, you're going to have to cut me off because sometimes, yeah. But, uh, so this other time I'm, I'm getting, and you know, another chat related thing. Cause I was the comms officer and, uh, we had like Microsoft net meeting was like the main, I don't know. Somehow we're using Microsoft net meeting.
Josh Datko: And they were getting, that's, that's what you're using. Like, so you're setting up just like these full things over satellite and it's just, yeah. And then it's just consumer software pretty much.
Dave Jones: I think, I think it's all changed now, but like, you know, before like the Navy kind of had its head around, like, you know, maybe we shouldn't, maybe we should actually have programs that are custom for this. Bespoke, bespoke stuff. Yeah. Right. Um, so, but yeah, so Microsoft chat had this feature where you could change the, change the text into like comic mode. And so you'd be chatting and you would say, I want to do comic mode. And then it's like a dog and a cat talking to each other and sometimes a bunny rabbit comes in. So, so I'm like, we're doing like a, a tomahawk strike exercise. So, so we, this is like, you know, it's like, you know, Hey, submarine shoot, shoot a missile here, you know, fire three missiles, you know, kind of, you know, this is like a serious exercise.
Josh Datko: Some big stuff. Right, right, right. Yeah. Right.
Dave Jones: You know, we're not actually shooting the tomahawk. Okay.
Josh Datko: I was going to say, is it, is it actually, is it actually doing that? But it's not.
Dave Jones: Right. No, we're like pretending you do a lot of pretending. So if you like pretending the military is, yeah, it's perfect. It's perfect for you. Cause you don't, sometimes you don't actually get to shoot real things, but so we're like pretending to fire these missiles. And you know, I was like, I looked, you know, I'm looking at this chat program. I'm like, Oh, it's got this comic mode. And you know, I was, I was probably bored. And so I clicked it and I was like, Oh man. So now it's like, here, here's the dog. And the dog is like, you know, submarine shoot three missiles, like barking at the cat. And the cat's like, Roger shoot three missiles. And I'm like, Oh, this is, this is so funny. I mean, this is like what? And so again, the captain comes by, you know, as he tends to do, and he's just like, what, what is this? Like, cause he thought that everybody could see, you know, that everyone, everyone was seeing cats and dogs. He thought like I changed it, right. He didn't get the concept. There's like a client local thing. Right. Right. He's like, why, why, why are they a dog? Why are we a cat like this? What are you doing? And I'm like, sir, I didn't, I didn't actually pick the cat. It's like, it just picked that for me. He's like, just change that back. Right.
Chris Gammell: So, so I would do some of these kinds of, uh, uh, okay. I'm sure, I'm sure we're going to pepper more of these stories in, but I would actually
Dave Jones: stop. I should stop.
Josh Datko: Okay. Okay. So we'll, we'll come back to that stuff. I'm sure. Okay. So, so, so as a, as like the cryptography and like communications type officer, how much, like, like how much interaction was there? Is it mostly like using it as an off the shelf item almost, or is there like, what happens if things break down? What happens if, you know, things are go awry? Like, is there a troubleshooting process for that stuff or is it mostly like a reboot kind of thing?
Dave Jones: Yeah. So there's like a lot here. I'm going to be air on the very conservative of saying, but I would like the, like a submarine generally is meant to be very self-sufficient. So there is a large amount of redundancy built into basically everything the submarine does. And so whether that's from communications to like independent power supplies I mean, it is, I mean, it's kind of the equivalent of like designing things for like, which I've never done, but like, you know, things like for like satellites or rad hard where you just have voting logic and these kinds of things. So, um, so a lot of the submarine is when it's the systems are engineered to have this kind of fault redundancy and, or there's enough equipment on board to be able to repair it.
Josh Datko: Oh, so like spares and whatever. Yeah. Exactly. Yeah. You wouldn't be as restricted on like weight as you would be in a space application, but space for sure.
Dave Jones: Yeah. I mean, there is like, there's only so many where you can stick things, uh, like on a sub, uh, but yeah. But yeah, generally like having one of anything is just like, just like if there's, if there's no backup for a part on your PCB, you're like, well, this is the only part, you know, that makes people nervous.
Josh Datko: Ordering one resistor from DigiKey, not, not a, not a great idea. Yeah. Right. Right. Yeah. Yeah. You're probably going to, you're, that's the one that you're going to go, you're going to squeeze too hard. It's going to go pink and right across the lab.
Dave Jones: Right. Yeah. So, so yes. So there's, so, so yeah, it's, it's kind of, but it's more like, um, there is some maintenance, um, in a lot of the enlisted sailors. That's kind of their primary responsibilities to be able to do like the maintenance at sea. And that's what their training is in. And that's kind of their main job. Yeah.
Josh Datko: So, and then on the, again, with sensitivity in mind, like the cryptographic type stuff on board though, is that like, so again, my movie, my boomy thing is like someone tears open a little envelope and they have the code and they type it in. Not so much. I'm guessing.
Dave Jones: Uh, so that was in October. They showed, uh, basically that what that's called is two person control. Okay. So I was never see on a ballistic sub, but the, uh, uh, and that, and that's where they do two person control for the authentication codes to like, you know, start world war three. Um, and so, so none of, uh, the things that I did required that, you know, two person control, what that means basically is two people physically have to be hands on something. Yeah.
Josh Datko: Like you cannot turn the key at the same time, kind of whatever. Right.
Dave Jones: Yeah. I mean, like, so if there was a message, like two people physically have to carry the message at the same time, like you have to do this really awkward. So this, again, it's like, you know, it sounds, uh, right. You know, so it sounds all serious. They're like, okay, this is, this is the like nuclear launch codes. And this is very serious thing. Two people are holding it. But when you have two people on a submarine trying to awkwardly walk down, not a very long or wide hallway.
Josh Datko: Right. Like, yeah. Right.
Dave Jones: So, yeah. So these are kind of like, so some of these kind of like, uh, just kind of funny situations I've, I always kind of picked up on.
Josh Datko: Yeah. I mean, uh, again, another, another, I mean, when I, when I picture you on the sub right now, I'm, I'm pretty much picturing like Kelsey grammar down periscope style. Like, uh, yeah, that was a good movie.
Dave Jones: I did like down periscope. Yeah. Yeah. Uh, I, yeah, I don't know how I lasted that long. I mean, I, it was, it was, yeah. Uh, there was, it was quite painful for the first couple of years and then I kind of like got into a groove and it wasn't so bad, but I mean, there's, there's a lot of funny times. There's a lot of like fun things, but a lot of it is just, uh, working very long hours is very painful. You're away from your family. So that's all the painful stuff, which I tend to repress. Um, yeah, the drudgery piece, right? I mean, yeah, yeah, yeah.
Josh Datko: Yeah. That sucks. Um, so like, so again, to go back to the cryptography piece though. So, so the kind of practical cryptography, like hands-on everyday type stuff that was more just encrypting messages that go back to shore kind of stuff or going up to satellites or whatever it is.
Dave Jones: Yeah. So it's, it's just kind of like, um, I mean, uh, yeah. So like basically every, anytime you have the option to encrypt a transmission medium, it would, you know, you try to do that. So it's, it's not, you know, as a submarine opera, you never really got into like what was doing or, you know, how'd this work? It was mainly just like, oh, I have to, you know, make sure this green light is on and I have to use this equipment to make this light green. Got it. Okay.
Josh Datko: Okay. Yep. Yep. I got it. Okay. Well, how about, how about you pepper us with another story here?
Dave Jones: Oh, okay. All right. So you have a list. I mean, come on. I did have a list. Yeah. So I had to run them. I think, I don't know if I said that, but I had to run them by my wife. Yeah. Well, so like, I mean, on the like joke telling thing. So like, you know, a lot of times it's like actually quite boring on a sub, you know, like it's, you're, you're on the Paris. I imagine.
Chris Gammell: Yeah. Yeah.
Dave Jones: So, you know, there's a couple of things you do to kind of keep yourself entertained. And, you know, I'd like to tinker and, you know, I'm in security. So I'd kind of like, you know, try to hack things and stuff. So there was this guy and we're doing this exercise and, you know, what you're supposed to do this exercise, you basically have to keep this log of everything you're seeing and you kind of are typing it at Microsoft Word and everything. Oh yeah. And so we're doing this exercise and this junior officer is like, he's got to type all this stuff in. Well, you know, Microsoft Word has this nice feature where you can do autocorrect.
Josh Datko: Yes. That's right.
Dave Jones: Right. And so it's, you know, if you, if you constantly misspell the, it'll fix it for you. But if you, you can add to the autocorrect dictionary. And so, you know, in this exercise, you know, we were like seeing fishing boats and pretending, you know, they were like warships and stuff. And so what I did is I changed like fishing boat to like a kind of worship in the exercise that would be like a much bigger deal. Oh my gosh. So this guy, so this poor guy, he's like, you know, typing these in and he's like, yeah, I know, see, we saw a fishing boat, saw this fishing boat. And then it gets autocorrected. I mean, it's like, you know, saw this destroyer, saw this destroyer. And it just sounds, if we had really seen them in the exercise, it would have been like a much bigger deal, but it just casually sounds like, oh yeah, we just saw a couple of things. Yeah, whatever. Yeah. It was like, whatever. Enemy worship.
Josh Datko: Enemy worship.
Dave Jones: Yeah. So the, so again, you know, the executive officers, the second command finds this one and he just starts like reaming into this guy. He's like, what are you writing? You know, like we, where did you, why are you making this stuff up? And he's like, sir, I don't know. I don't know what's going on. I thought I'm writing fishing. I'm writing fishing vessel. And he's like, you did not write fishing vessel. Clearly says, you know, destroyer. I'm like, why are you lying to me? And yeah. So he, he got it pretty bad.
Josh Datko: But yeah. Oh man. Yep. That's great.
Dave Jones: But yeah. But yeah. So yeah. So then, yeah. So after like all the submarine escapades and then I went to work. So this is a kind of how I got more into electronics is I went to work for a defense contractor in, as an embedded software engineer.
Chris Gammell: Okay. Yeah. Yeah.
Josh Datko: And so, and you mentioned little black boxes and stuff like that too. Yeah. So.
Chris Gammell: Yeah.
Josh Datko: Okay. Yeah. It might be coming up against the not allowed to talk about what's inside of it, but I'd be curious about the more, more generally about like working embedded software in what I, what I presume is a kind of slower environment just because of approvals. Yes. Long timelines and stuff like that. So what was that like?
Speaker ?: Yeah. Yeah.
Dave Jones: Yeah. I mean, it's very much like the classic waterfall style engineering development and you know, it's, it's because these are, you know, government projects, they have very large budgets and very large timelines and you know, they spend months doing systems engineering, which is basically you know, coming up with requirements and putting them in spreadsheets for a very long time. And then mapping all these requirements to like software requirements and hardware requirements and mechanical requirements. And then, then you start, you know, doing each of these and it's like, you know, it all looks very good on paper. Um, cause you have nice Gantt charts and, and yeah, of course, you know, the, the four
Josh Datko: weeks for design, four weeks for building, four weeks for testing, you're done.
Dave Jones: Yeah. So it's very like very much process oriented. Um, yeah. Uh, you know, this kind of thing. And so, uh, I mean, it was, you get to work. I mean, I got to work on, I, you know, at the time I think was some kind of super cool stuff. Um, you, um, it is, it is, I've realized though that like, sometimes it's nice, it's good for engineering to have constraints, um, and especially in time and money. Uh, so, I mean, it's a much different challenge. Yeah.
Josh Datko: When I mean like a design document or a system engineering document is a constraint. It's just not the one you're talking about. Right.
Dave Jones: Yeah. And so it's like, you know, when you're doing things that are like, um, you know, I would imagine like, you know, safe, you know, especially, you know, safety or for the military. I mean, there's just so many extra requirements where it's like, you know, it's like, well, you know, uh, whereas a consumer product, it's like, well, you know, we could, we could do this thing. We could just be this much more efficient or this much, maybe it doesn't, there's not as much failures where you go that extra 20% and spend a lot of extra effort to, uh, I mean, over-engineer basically, uh, to prevent.
Josh Datko: It asymptotically approaches this, this ideal thing that like. Exactly. You can spend four years doing it, but why should you? Because you have competitors in a marketplace, you have competitors. Whereas in a government thing, it's usually you've already won the contract. So why not? Yes.
Dave Jones: Yeah. Yeah.
Josh Datko: Yeah.
Dave Jones: And I mean, it is for, I mean, I, I tend to be a bit cynical, uh, but you know, you know, the, for the reason is, you know, like some of these things are obviously very, you know, national security or, or safety. So I mean, there's, there's reasons. Yeah. Okay. Okay. Yeah.
Josh Datko: I mean, what kind of, um, again, stop me if you're not allowed to talk about certain things here, but like, like what kind of language were you programming in? And yeah.
Dave Jones: So mainly, it mainly was C, um, you know, C and C plus plus. So I, I had, this was back. Yeah. So, so like I said, I was, I was mainly a software computer science, uh, undergrad. And then, uh, and then I started doing this and then it was mainly in C plus plus. And this was actually, I had been on the sub for five years. So I really hadn't programmed.
Josh Datko: Right.
Dave Jones: Right. Uh, in, in, in like five years and then I get the job as embedded, uh, programmer. And so I think, I think a lot of my military experience helped out cause I was like basically working on some of the products that I had used. Oh, that's kind of cool. Yeah. Yeah. So that, that was, that was kind of neat. So, um, but like at the beginning of there was like, oh yeah, I remember how to do this. Volatile. Yeah. Like, oh yeah, yeah. So, so it was like, it was kind of a steep, uh, curve there in the beginning, but I think I picked up pretty quick. And then, um, yeah, embedded C and then I went back to grad school, uh, at Drexel university and it kind of focused on, uh, security. So again, it was a computer science degree focused on security and anonymity, um, kind of like things like tour, uh, you know, kind of like studying these kind of, yeah.
Josh Datko: Yeah. Could you explain what tour is for people that don't know?
Dave Jones: Yeah. So tour is, um, basically an overlay network system. And so it's, it runs on top of the internet. So it, it's a network on a network. So that's what overlay means. And its main purpose is to provide anonymity. Um, and it, and it originally it did this mainly focused on your IP address. And so tour, uh, got started, uh, actually as a defense project and the, yeah. So the defense aspect is it of it is, well, you can imagine there's, you know, some military analysts and they, uh, you know, are in the military and they're, and they're, you know, basically Googling, uh, you know, what other countries are doing. And so if you do this, well, I'm a normal internet connection, like your, your source IP address is going to show up in some log somewhere. And if someone does the reverse lookup, they say, oh, this is interesting. There's a us.mil, uh, person like, you know, doing the search. Isn't that interesting? So that, that, you know, I think the original, um, you know, purpose was like, well, maybe that's not a great idea. And so, uh, there's these two, uh, the main researchers, Roger Dingle nine and Nick Mathewson, uh, kind of proposed this, uh, protocol basically of trying to hide your IP address by going through a series of hops, um, called nodes, uh, through the tour network. And so that when, when, you know, you have three levels, I think three levels of encryption it's been a while, uh, basically you encrypt packets, you send it to the first node. That first node strips it off like an onion. So that's kind of what they're, they're, uh, logo is this onion, right? Onion tore it off. Yeah. And then, uh, it sends it to the next node. It strips off the next layer, send it to the third node. And then that third node sends it to, which is called an exit node, sends it to the final destination. So that destination server, when it looks up your IP address, they get the IP address of the exit node, not your IP.
Josh Datko: Oh, wow.
Dave Jones: Uh, and so this is, you know, solve the immediate problem, but one of the things they had realized that in order, and this is a problem in, in kind of any anonymity. So I did some research into anonymity systems is that in, you know, you can't, uh, you can't hide by yourself, right? Like you can't go into a crowd of one and be anonymous. Oh, right. Right. You need to have a big crowd in order to hide in. And so part of the design of tour is that they want to, uh, get a large number of nodes. And so there's this giant pool of nodes that can help mix and, uh, the traffic as it goes through.
Josh Datko: Got it. Okay.
Dave Jones: And so now it's used. Yeah. So now, uh, I, I don't know if it's being used for the military or how long that lasted, but I, you know, a lot of the main application, um, is like for countries where there's lots of internet censorship, uh, so you can get, you know, uh, and there's, uh, I think one example was a few years ago, but like in Turkey, they've tried to block Twitter, but if you use tour, um, you can get to Twitter. Uh, so things like this.
Josh Datko: Yeah. That's good. That's a practical example. Yep. Yeah. Cool. Okay. And so like when you went back to grad school, it's like, I, first off, I've never heard of, I guess I should assume there are, but I didn't know there were security based programs. So what was that like?
Dave Jones: Yeah. So it wasn't really, I mean, it was a generic computer science. I think now there is, um, now there's starting to be like cybersecurity, uh, stuff. Um, so I mainly went for computer science, but I just kind of focused on security classes. So I had this professor, uh, her name is Rachel Greenstadt, who is, uh, uh, you know, fabulous professor. And she taught mainly the secure privacy and she ran the privacy and security lab at Drexel. And I basically took every class that she offered. And so, you know, one of the classes was like software security and you learn how to do, uh, shell X, you know, basically how to do stack overflow and all these kinds of buffer exploits. Um, so you get, you do those assignments. Uh, those were a lot of fun. And then she, uh, has a lot of classes, you know, she focuses on, uh, anonymity stuff. So then I took, I, there was like, you know, four, four classes of, of like security related, uh, stuff out of the computer science degree. There you go.
Josh Datko: Okay. That's cool. That's cool. Yeah. So then, so like, I guess, I guess what I'm always getting at with security. So first off, I'm always curious how there's so much money in the security industry. I get it from a practical perspective, I think now, but it, it still never stops boggling my mind. Yeah.
Dave Jones: Yeah. Well, I mean, there's like a few, yeah. I mean, that's where there's a few levels there. I mean, so one is like, Oh, as a business owner being in there, um, and then kind of seeing where, you know, how are some of our clients like where, and then I think a lot of it is, uh, so not everybody, I mean, um, you know, not everyone has this kind of, well, so there's not a lot of people in security, like compared to a normal, like, uh, like software engineers. Right. So like if you're a software, especially with software, there's, you know, comparatively a lot of software engineers to software engineers who know security. Um, you know, there's fewer hardware, uh, electrical engineers, fewer of those who like, you know, also do security. So it's just this subset of, uh, like a pool who, who can do this kind of thing, I think.
Josh Datko: Yep. Okay. So then from a practical perspective, like, so as like an embedded software engineer now, uh, embedded software security engineer, like what is, what does that end up meaning at the end of the day?
Dave Jones: Yeah. So, uh, I mean, what it is, I think a lot is so as a, so then there's also a different there's like different, uh, hats or yeah, well, there's like the hat terms of the overload, but let's just say different sides. So, um, right. If you're, if you're a developer and if you're working for like a defense contract where there's certain, like, uh, you know, where, where there is this kind of nation state, like level, uh, attack, um, threat it's, there's a lot, you know, it comes down to basically writing software that doesn't have, is not filled with vulnerabilities. Um, and so there's a lot of emphasis put on, uh, you know, making sure like the code is written in a certain way. There's lots of code reviews. There's lots of standards. It's, you know, a lot of time is spent on code quality, I would say. Um, whereas like a consumer, you know, if you were like writing some IOT thing and you're like, Oh, I got my code to work, uh, you know, pass my unit tests and it functionally could do. So I guess, I guess a lot of security is negative testing also. Right. So, so if you, if you do a test, whether it's software or hardware, um, you know, you're like, I need these things to be in the spec. So if I'm making the circuit, the circuit has to have a response at this frequency. Right. And you can do that and you could, you know, say it passed this test, therefore passed the specification. A lot of security is trying to get it to do things. It was not designed to do. So, and these are just like negative tests. So like, can you abuse this circuit or this software in a way that wasn't designed to get a failure of the system that you can use to exploit. Um, and so.
Josh Datko: Right. So getting access to the, uh, cryptographic keys or. Yes. Yeah. Getting root access, that kind of thing. If it's a higher level system, that kind of thing.
Dave Jones: Exactly. Exactly. And then even, you know, for hardware, um, I mean, it's this, it's a, it's a similar kind of thing. It's like, can I get this system to, to, um, you know, get, get it outside of its operating conditions, either the voltage or current and does it, you know, and, and so I gave this talk last year at a DEF CON where I did, um, voltage glitching attacks on, uh, Bitcoin hardware wallet, um, the Trezor. And so what I was using Collins, uh, chip whisperer device, and we were trying, you know, essentially the idea with the voltage glitching is you try to get the microcontroller to operate outside of it. You know, there's that nice curve in the data sheet that says, keep, keep everything in this nice parameters. And we guarantee, you know, everything will be fine. And so, you know, security again is getting things operate outside of those parameters. So voltage.
Josh Datko: So what were you trying to, so you were basically tugging on the, the voltage rails of the wallet. Yeah. Yeah. And then what were you hoping to do with that?
Dave Jones: So you basically try to get some, uh, like fault, uh, to be introduced where the fault is, um, some sort of memory, uh, memory corruption. And so with the way this, uh, can be in a way this manifests is say you were about to read from flash. And so, you know, um, you know, maybe the flash bites that it reads, aren't the same as what's actually in flash, right? So as it's reading from flash and it's pulling the data out, uh, it no longer reads the right value, or it could be a memory that's on the stack. So if you're executing a loop and the loop is supposed to execute a hundred times, but you apply a voltage glitch, maybe it only executes 99 times. And is this a problem or not? Well, you know, maybe yes, maybe no. Um, if you're, if you're doing a security, if you're looping for a security reason and you're able to, uh, get the loop to, to misbehave in a way that the developer didn't intend, you know, you could, uh, so what we were specifically trying to do is actually this loop attack example. So, um, the Trezor has this feature where if you enter the pin wrong so many times, it just goes into a busy spin loop. So it's just a, you know, while it uses a Uint 32 and it just, um, just loops in a, the processors in a hard loop. And so the idea that we were trying to look into, which ultimately, uh, didn't, you know, didn't work, but we were trying to apply voltage glitching while it was in the loop to get it to bust out of the loop. And if you could break the loop, then you would, could have more free tries essentially to guess the pin. Oh, I see.
Josh Datko: And that would allow you to then start doing like brute force attacks and stuff like that.
Dave Jones: Exactly. Exactly. So we, so that ultimately was not successful. Uh, we did, uh, find some other things, you know, so for example, the Trezor, you know, we did try to do clock glitching as well. So clock, so voltage glitching is you do this by essentially shorting, uh, the power supply clock glitching is then inserting, you know, trying to make the, uh, like messing with the waveform to the clock and such that the hope is you get the processor because of the pipelining and all this, you get it to essentially skip an instruction. And, uh, so we tried it with clock glitching. Um, it wasn't effective, but we did find that the, they did not, there's, um, this microcontroller, which was the STM 32 F2 had a basically bit called clock system security. And, you know, they, if they turned it on the microcontroller was, could detect if the clock failed and then, you know, could do everything. So at the end of the day, that's, that's one of the changes that they did incorporate is they turned on this clock sensor. Okay. Someone. Yeah.
Josh Datko: And so, so you guys weren't trying to do it to actually get anything out of it. You're just doing it to get the research of it and understand where there might be vulnerabilities.
Dave Jones: Yeah. I think, you know, so like, you know, we do, you know, so, you know, we do engagements where we were doing a penetration testing or audit of someone's product. This, I think I was just curious on, I mean, I, I had, um, I know I have, some of my clients are in the like cryptocurrency space. You know, I've kind of like dabbled in there too. Uh, I know. Uh, and so, um, you know, I had, was like, well, Hey, people are making these, like, you know, storing lots and lots of money on a STM 32. Right. It's essentially.
Josh Datko: That's, that's a little crazy.
Dave Jones: Yeah. And so like, well, you know, maybe there's, you know, maybe, and then usually a lot of security research is like just looking under the rug, which no one had looked before. Um, so it's like, huh, like, like there's, uh, so, you know, so I'm, uh, next month I'm giving a talk with, uh, Dimitri Nidos and Thomas Roth, uh, at, and, um, CCC in Germany. And we're kind of continuing some of these wallet, uh, hardware attacks. And, uh, Thomas gave a talk, uh, last year about some industrial internet of things. And he basically got a bunch on eBay and then just found, you know, he like, I don't know like five or like six of them. And basically all of them had like some decent security problem. And I just don't, you know, maybe no one has like decided to look at it. I mean, so some of it is, um, you know, you know, if you look under the rug, you're going to find some bugs.
Josh Datko: Right. Uh, so we'll tell us more about that talk. I mean, how much are you willing to talk about that talk?
Dave Jones: Yeah. So it, uh, yeah, we, uh, I can talk about a little bit, you know, we want people to kind of, I think they're going to be, uh, streaming it. I think it's my first time going to CCC.
Josh Datko: So I think they, they definitely at least, uh, put them up after the fact.
Dave Jones: So, yes. Okay. Okay. Cool. So, yeah. But yeah. So like I said, it's, uh, Dimitri Thomas and I, and we're kind of looking a little more broadly at some of the, uh, Bitcoin, you know, cryptocurrency hardware wallets. And just, just a quick background of what those are, um, is that essentially if you do anything with cryptocurrency, it all comes down to, uh, public private key pairs. You know, you have to store your private key somewhere. And so the thought is, well, you know, if you, if you did it on your phone or you did it on your desktop, you know, like the software is obviously insecure. So let's just put it into quote unquote hardware, which is just software running on a, right.
Josh Datko: When you say private key, it's totally like a, what, 2048 type of character string or something bigger.
Dave Jones: Uh, yeah. So Bitcoin uses, uh, um, elliptical curve photography. Uh, and so, so there's basically, so that, you know, if I'm thinking of this like, uh, kind of diagram. And so you have symmetric cryptography, uh, which is both parties have to have the same key in order to communicate. And asymmetric cryptography generally is there's a public private aspect of it. So public private asymmetric are sometimes used interchangeably. Um, so with, uh, Bitcoin, they use, uh, so then in, inside of asymmetric cryptography, there's different, uh, schemes that you can do. RSA, um, is kind of the classic one. Um, that is like, you'll see like RSA 2048, uh, bit key or a 4096 bit key. Elliptical curve cryptography, uh, has the benefit of having much smaller key sizes for, uh, roughly the same equivalent security for the key. Bitcoin uses elliptical key cryptography.
Josh Datko: Okay.
Dave Jones: Then more specifically they use, uh, it's the curve like SECP 256, uh, K1. So then there's different elliptical curves that can be used in different, uh, elliptical cryptography. And then, um, yeah, but basically it comes down, there's a private key. It's 256 bits long. That key can sign operations. Uh, so again, with a asymmetric cryptography, if you sign something, you keep the private key, but anyone who has the public key can verify it. So this is essentially how you transfer money, uh, in Bitcoin. And so you have to keep. So it's really, really.
Josh Datko: Your key plugs in though. And then it like, that's what, when it's signing, it's saying like, okay, push your bits through this engine. I have, I have a private key stored in here. And then it's out that are encrypted or whatever.
Dave Jones: Exactly. So yeah. So signed, right. So you, the, the kind of whole idea with the hardware wallet is that the, the, the private key stays in the, uh, memory of the microcontroller or secure element, and it never leaves into the host computer. And so you have to send over the transaction. You say, Hey, hardware wallet, please sign this, you know, please authorize, you know, sending a funds from a to B the hardware wallet. And generally they'll, they have, they have all have some sort of display where they say, do you want to, or do you want to send all this money to Chris? And you have to say yes or no. Of course you do. And yeah. And then, uh, you, you know, you say yes, uh, or no. And then the response comes back to the host and then the host, um, you know, uploads it to essentially the Bitcoin network. And so it can do all that decentralized kind of stuff, but it all comes down to at the lowest level. It is just, uh, an elliptical curve, digital signature algorithm or ECDSA. And it's just the sign operation that happens in the microcontroller or, or whatever hardware.
Josh Datko: So the ability to, to either extract that key or mess with that in between stage and insert some other key, you could basically pretend you're someone else and pretend to take their money, that kind of thing. Exactly.
Dave Jones: So if you, if you can get to, you know, if you either, uh, can, uh, get the hardware wallet and extract it, um, you know, you would be able to transfer their funds. If you can observe, um, you know, maybe there's some parameters. So these are called side channel attacks. So normal operation of the device, but say it leaks information, it could leak, uh, power information. It could leak other kinds of emissions. And to say, so say you monitor those, then you could potentially extract the key or there's other, I mean the, the, like also the wrench attack works. Where are you? What's that going to say? What? So there's the classic. Give me your key or also hit you with the wrench. Yeah. Okay. Yeah. So there's always like, you know, so you always have to worry about the human, the human element,
Josh Datko: right?
Dave Jones: Yes. Yeah.
Josh Datko: Yeah. Yeah.
Dave Jones: Yeah. So we, um, so yeah. So, uh, you know, Dimitri's background is looking into, uh, you know, he does, he's, he had a PhD in some, uh, silicon attacks. He does a lot of, he teaches a class that goes into a lot of glitching stuff. So we also passed the show twice. So yeah. Yeah. Yeah. Yeah. Yeah. So yeah, we, so I think he saw my talk and then we started chatting as a kind of how we got involved. So there, you know, there's gonna, there's some glitching stuff. Uh, Thomas is a very impressive reverse engineer among other skills. And so there's some, uh, you know, soft, some of that. And then I'm kind of, uh, you know, looking at some of the glitching stuff again, like I did last year. And then I'm kind of looking at, you know, hardware implants, uh, which I gave that talk a few years ago, Defcon kind of dusting off, uh, because the hardware implants have been in the news. Um, they have.
Josh Datko: Yeah. Well, why don't you give a recap of that? I mentioned it briefly when I saw, uh, Joe Fitz and Joe Grant were here in town. And then I mentioned that briefly, but I really didn't do a good job explaining what it is. So could you explain that whole situation?
Dave Jones: Yeah. I, to the extent that I followed it. I mean, I think I remember reading this and I said, this is, this is just crazy. So, but I think this is the Bloomberg story. Yes. This is the Bloomberg story, uh, about, um, uh, super micro computers. I think so that they were, they specifically said there were super micro servers that had essentially their claim was there was a backdoor. They, I think they allegedly said it was a Chinese backdoor and they had, you know, infiltrated, you know, Apple, Amazon, uh, Google cloud infrastructures with this backdoor into their server hardware, which I think was the claim. And so, uh, which is, uh, you know, if that's true, that's, I mean, that's, that is certainly newsworthy. Right. Yeah. Right. Yeah. Um, and so, but like, you know, as people started scratching the surface and I think, uh, both Joe Fitz and Joe grand were interviewed for this, but they didn't, I don't think they like knew the, there was like, saw all these weird details that were coming out, but. Uh, you know, I think when I eventually looked at it, I, there's this picture and it's on the cover of Bloomberg and there's like this little chip that's like tinier than the pencil point. And it's like on the cover and they're like, this is the hover implant. We found it. And someone, uh, had, you know, did like the reverse image search and, um, you know, figured out what that chip was. And it was like an RF, um, I'm blanking on the name. It basically could, it's like not really a multiplexer, but could like pass RF into two different, uh, signals. Oh yeah. A splitter or something.
Josh Datko: Yep.
Dave Jones: Yeah. And so it was like, this is not, this is not, you know, they were claiming this is like some nano computer. This is like this crazy technology. And I'm like, this is like you use to detect if you're in RF field or something like this is not, uh, the hardware implant. And then, um, so then, so that detail started to get sketchier and sketchier. Like this doesn't like things aren't adding up. And then I think, uh, you know, both the Joes kind of, you know, talked about cause they were interviewed in there and then they kind of came out later and they're like, and yeah, if you were doing a hardware implant, you wouldn't do it this way. I mean, there were, there's just so many easier ways. Uh, like you would just need to be able to reflash, um, like some of the components on there. Like if you just grab the server and you know, uh, these servers have a spy flash on them to keep some of the bootloader and all these things like, you know, you can just pretty easily just, you know, modify the bootload, you know, modify that spy flash code. You can, there's just all these other things that are way cheaper to do than developing a nano nanocomputer and somehow make it look like an RF splitter, you know?
Josh Datko: Right.
Dave Jones: Um, so yeah, so I've, uh, that, you know, so that occupied like the news, I think for a few weeks there. Um, but when I had, uh, so my first DEF CON talk was when this NSA, uh, catalog was released. Um, they had actual, actual, uh, hardware implants that, you know, are allegedly come from the NSA and they were, this is how they would like, uh, get into.
Josh Datko: And this is like the one where you, you have, uh, you do backscatter on like a VGA cable or something like that.
Dave Jones: Yeah. So that, that Michael Osmond did that one and he used a hacker F and basically, uh, did an RF retro reflector. Um, and then, yeah, so he've illuminated with basically a radar to this transistor and was able to read out some of the serial data, uh, on whatever bus he was targeting. The one that I did, uh, was a device called the chuck wagon. And I, there was like some talk in there about like, there was some implant that was over I squared C and it was, then they had some GSM, uh, modem capability. Right. So they, so they clearly, it sounded like, well, you know, over a GSM network, they could talk to this implant, which would then inject commands over I squared C. And I was like, Oh, that was, you know, you know, that's interesting. Like, how would you, how would you do that? And so I was like, you know, you know, let's start thinking about like, what are the I squared C buses on a, on a normal, like X86 server? And, uh, I was like, well, Oh, you know, this is interesting. Like every X86 server, you know, has this VGA port that goes out. And, uh, you know, what do you know? VGA has E did, uh, to get the monitor resolution and that's I squared C and it also has power. Right. You know, you, so there's like, and so what I built, right.
Josh Datko: Yeah.
Dave Jones: So right there. And no one, no, you know, you know, you hear in the government, like, you know, when I was there, they were like putting epoxy and USB ports and it was like, Oh, USB is evil. Right. Um, and so it's like, yeah, everyone's like USB. I gotta lock that down. Right. But like every, you know, every desktop I know has some display port, uh, otherwise it wouldn't be very useful. Uh, and then servers have them so you could, you know, get the crash cart. So, um, so I took a, I took a BeagleBone and I had made with a SparkFun, uh, this thing called the Crypto Cape. And I had put some like security chips on there. Um, and it had, uh, an app mega 320 P and it had, you know, this is basically just like a security dev board and I put it on the BeagleBone and I put a VGA adapter to it. And then I put a GSM modem on there. And so I plugged it, you know, so the demo that I gave is I plugged it into my laptop and I had, you know, had to assume basically you had, you know, somehow gotten access, a software exploit where you could talk to the I squared C channel. But basically I, you know, at Defcon, I was able to text my hardware implant and then it received the GSM text and then inserted a command over I squared C to the laptop and then ran something. Uh, yeah. So, uh, yeah. So, uh, so we, so I kind of done these like hardware implant stuff, you know, uh, and then there's a whole NSA play set, uh, which I think Dean Pierce came up with that name. And there, there was a bunch of people who had kind of taken some other projects, but yeah. So, so hardware implants, um, but yeah, they're generally like, you know, so they do, you know, they are a real thing. Um, and they're generally not, I mean, I think the conclusion of this NSA play set stuff is that, uh, they're not like, you know, you don't need a billion dollars to make one of these devices. Um, you know, they're, they're able to be made and, uh, yeah, I mean, they bypass.
Josh Datko: Well, you do, you do it maybe if you want to do that, but you have to do it through the, uh, the defense contractor, you know, hierarchy like you're talking about. Right.
Dave Jones: Right. Yeah. So I, you know, I've never heard back, I've never gotten any feedback, you know, from the government. If like, you know, they took my design ideas from my beagle bone and the better hardware implant, but, um, right.
Josh Datko: Right. Who knows? Yeah.
Dave Jones: But, uh, yeah. So yeah.
Josh Datko: What about like generally working with the government? I mean, like, so that's something that I think, you know, people listening probably are doing. And obviously, you know, you've done that in the military as a military contractor and now as a security consultant, I assume to people that are working with the government or directly to the government. Like, what is that interaction? And then I'm sorry, I should be much more broad about this, the U S government. Uh, I don't assume other governments. Um, so what is that process like in general? I mean,
Dave Jones: yeah. So I, I, as, as now a civilian with no connections, I like, I do not have any government contracts. We don't do any government. And, uh, part of that reason is, uh, you know, so you'd have to maintain a security clearance and I have a pretty epic story about a security clearance, which I'm not, which is definitely better told. Yeah. I know that, that one. Take Josh out for a beer and then he'll tell you that story. That one is pretty good. Uh, but, uh, also my, so my wife was, uh, born in Iraq and I, uh, so when, you know, when we go to war with a country that you, you marry someone there, uh, it is not easy to get a security clearance. And so I am not, I, I, I am very much done with the security clearance process. Right.
Josh Datko: So, um, so yeah, so I don't have any private citizen and no chances, no chance or interest in going back.
Dave Jones: Yeah. We're done with that. So, um, uh, so I, I've never like bid on a contract or anything like that, but like, uh, you know, I've seen it kind of as a contractor and, um, you know, being in the military and it's like, I mean, from what I understand, it's like, you know, if you're actually bidding on these contracts, it's like, you know, some of them can be quite a lot of money and you don't like, they don't actually pay, you know, they don't pay like net 15. It's like more like net one year, you know? So it's like, if you're a small company, um, and you take on a lot of risk.
Josh Datko: Last year, last week, I think, what to about like net terms and stuff like that. Oh yeah. No, yeah. I tried that, but yeah, the government doesn't care, you know?
Dave Jones: Yeah. Right. So it, uh, I mean, I, I kind of vaguely know of some small companies that do defense contracts and it kind of, you're in there and you know how that works. I mean, I get the sense it's very, uh, it's a decent business, uh, you know, like financially. Um, but yeah, there's a lot of like headache, which there's a lot of bit, you know, paperwork. So I went from like the military, which is a lot of paperwork to working for defense contractor, which is less paperwork. And now I'm quite happy to like do less paperwork. Uh, so I'm deescalating paperless now. Yeah. Right.
Josh Datko: That's good. That's good. So, well, what are you, what are you excited about in the security industry or the hardware industry these days? I mean, what does it, what does it look like from your vantage point as a security researcher?
Dave Jones: Yeah. So, I mean, I think it's still, I mean, so, I mean, people are getting, um, I mean, so like the ocean is, is the, the level of the sea is rising a little bit, um, with how some of the hardware, like even on consumer hardware security, like it, you know, it's not, um, you know, there's less people are starting to get the hint. I think, um, where like, Hey, it's not good to leave like, uh, you know, maybe JTAG open or serial ports open or, and so I think some of that slowly, uh, getting there. I think a lot of that is to like some of the, um, silicon vendors are starting to make microcontrollers with more advanced security features. So, uh, you know, certainly like that, that helps, like if you're sourcing components, like now you actually, there's more like even, um, you know, most vendors, I think at least have a security chip, uh, no, there are obviously ranges, you know, of the kind of quality there, but like, um, you know, there, there's at least more options. Like, and so the silicon vendors are kind of making people aware, and that's trickling down to the field application and engineers. And like, so people are kind of like hearing about this more, which is, I think is kind of bringing it up. Um, but on, you know, also the, the attacks get more sophisticated and the attacks get cheaper. So it's always this back and forth, um, cat and mouse. Um, so it's, it's, yeah.
Josh Datko: Well, I think about like the, so the people listening here, right. They kind of, they, they span, span the, the run, run the game, sorry, run the gamut of like, you know, people doing stuff in their basement as a hobbyist project up to people that are actually doing, um, you know, hundreds of thousands of units, right. Some, some people listening are doing that stuff. I assume the ones on the high end are more likely to be thinking about security, hiring security consultants. Um, you know, I think that's a lot of people are doing that. Being asked about security or actually are, you know, at risk of being targeted, but what are some best practices kind of going, even sliding back down into the, into the hobbyist level? Right. So like, I assume that if you're learning, maybe you don't have to do it right away. You know, if you're just getting started and embedded, but as people start building products, what should, what should people be thinking about or best practices they should be doing when they're designing new circuit boards and that have micros on them?
Dave Jones: Yeah. So a lot of it is isolation. So one, so one way to think about security is in the heart and kind of like from a, so on a personal or hobbyist level is isolation. So if you make your like a, you know, wifi garage, um, Oh, so, so I should step back and say like, so really, so there's this term called threat modeling, which is a security industry term. And really it's kind of just like doing a risk assessment. And so, um, uh, this sounds like a very security kind of focus thing, but basically everybody, every engineer does this, right? So if you're making, uh, you know, trying to make out your wifi garage opener, right? You would say, well, well, okay, I can do it this way. Um, I could use this new part and you know, maybe I don't know how to do this, or maybe this is more expensive, you know? So there, you're already doing this kind of trade-off analysis.
Josh Datko: Right. Like what can, what can go wrong? What's exactly what should I think you're thinking about? Right. And security is one of the other inputs.
Dave Jones: Yeah. And so the threat, um, doing a threat model is just the kind of like putting a name to the kind of security minded thinking of it. And a lot of it is thinking like, you know, well, how is this going to fail in, you know, an unexpected ways, which kind of sounds like an oxymoron. Like, how do you know when it's you, how do you know it's going to be this unexpected? Right.
Josh Datko: You don't know what you don't know kind of thing. Right. Right.
Dave Jones: But if you, if you, you know, took the like, well, okay, I, I'm going to replace my, uh, garage door opener. Right. And I want to make this, uh, like Laura. Right. So I got the nice, I got a nice range on my garage door opener. I can open it very far and all this stuff. And so if you start thinking about it, you're like, okay, well, you know, um, so I can do this. So you, you, you kind of make the thing first and like, okay, cool. It works. I can do it. And then the next step is basically like, well, if I can do it, like who else can do it? Uh, you know, can somebody else open the garage door? And then, so like to think about that question, you're like, well, okay, well, how does, how would someone else open my garage door? Like, so if I can clearly make the transmitter and I bought the part of DigiKey and someone can clearly buy them. So what do they need to know? I mean, they need to know that it's Laura, you know, so like, okay. So they find a Laura transmitter and then, uh, you know, what is the thing that makes it, um, like this access control? So how, how would you talk to your, uh, receiver? Is it just who's in charge here? Right. Yeah, exactly.
Chris Gammell: Yeah.
Dave Jones: Yeah. And so this kind of process, so this is the like threat modeling process is the kind of security name for it. But if you, um, you know, it is not outside the realm of any engineer to do this. Uh, cause I think basically every engineer, it's just that there's the, you know, the practice and the mindset is something that you just kind of have to purposely think about versus like, right. Uh, you know, yeah. So if so for that, yeah.
Josh Datko: I was just going to say, I, I, I think that like, so I did a Laura project recently and I, you know, I basically didn't think about some of that stuff too. Or I was like, oh, well, you know, it's not that big a deal if people know this stuff, you know, or it's not, it's not that big of a concern right now, but then it, you know, I, when I think about projects, you know, you say that and then the project moves on and you forget about it. And then it's like, so if you're not thinking about it up front, you know, it does never get baked in later on.
Dave Jones: Yeah. And so, and so some of this is just formalizing it. So like, um, I mean, so, I mean, so based there, I mean, you, you have thought about it, right. So it's like, but so if you took it, I mean, I'm sure you're, you thought about, well, the voltage, you know, from the battery has to be this and this, right. And, uh, you know, that's probably written down somewhere, some spec and, you know, there's like, people can go look up and say, Hey, you know, what's the battery voltage of this? Oh, well, you're going to sit, it says in this design document, you know, if, if it had matured to this level, right. There's some document that I'll say battery has to be between this. So security, really security engineering is kind of just like also formalizing that. So if you, uh, if it could very well be that this is not a big deal, um, you know, because of the risks involved or whatever, but the fact that that's written down is like, well, you know, we assess that the risk of like, you know, uh, you know, something, you know, someone inadvertently doing this or this is low because of the following reasons. And, uh, you, you know, you put that down, uh, in a document that is, you know, in some sort of security document. And then if the project does changes where they're like, Hey, cool. It wouldn't be great to use this wifi, this Laura based opener. Why don't we put this on like all this industrial control systems and we'll just open all these valves. Right. Like, cause it clearly works. Right. Let's just do that. And, uh, so people were like, okay, yeah, the voltage works. This is great. All the specs are great. Oh. And then, then there's that security piece. They're like, oh yeah, we do, we do this not to be a risk because it was meant for like, you know, some like prototype thing. And then that hopefully is the trigger, like any other requirements spec that, you know, and I'm being.
Josh Datko: To think about it and be like, what is our actual risk here? Yeah. Right.
Dave Jones: Yeah. Now I don't know to be like, that is my, like, uh, I mean, I would very much like to think that, you know, there's this security engineer kind of process and all these products, but I unfortunately don't know many like companies that, that, uh, you know, have, that do, I mean, some of the big ones, obviously the big ones do. Sure. Sure. They probably have a team though too, right?
Josh Datko: They, they, they, and they've already responded to other things. So they get called, you know, they've, they've had a security problem at some point they keep, they retain a team and then they're like, yeah, we should probably call these people the next time we build a thing, you know?
Dave Jones: Right. So, so yeah, I mean, it's just, it's like, um, I mean, so there is this, you know, it is like any other discipline of engineering. There is, you know, there's lots of decent books and there's lots of mindsets and there's ways you can get into it. Um, but it's, it's, you know, if you looked at it from a, like, um, you know, QA testing, like a traditional engineering process that didn't really have a security focus, it's a lot of just negative, uh, you know, like you give, you give this product, you're like, Hey, I'm all done. Passed all the positive, uh, QA tests. You give it to somebody like, Hey, try to break this thing in a way that, you know, we didn't intend. And then it's like, Oh, turns out, um, like I can always make this valve, uh, you know, open, but I can make the indicator stay closed. So this is one of Joe Fitzpatrick's examples. Um, yeah. And then, yeah, that could be a problem if the, like, if you're cycling an industrial control valve, but it's reporting that its status is not changed. Right. So this is, that's bad.
Josh Datko: Yeah. Right. I've worked in facilities and that's, that's real bad. Yeah. Yeah. Yeah.
Dave Jones: Um, so yeah. Okay. So, so yeah, I think we tried to help, you know, so I mean, so now, yeah, so now it's, there's like four of us and so now, um, you know, started off just by myself, uh, working on the crypto Cape and, and doing conferences and then now have slowly got more work and now there's four of us doing this. So we generally try to like help. I mean, what I really like doing is, is being the kind of security engineer working with an engineering team. So if there's a team.
Josh Datko: So you're called in because they're not retaining an entire team. You're more of a consultant that comes in and plays that role you kind of described. Right.
Dave Jones: Right. So like for new product design, they're like, Hey, we want to make this thing. Uh, you know, and I'm like, I mean, I, I really like, I mean, I, I like breaking things. I mean, that's like part of the fun of security is attacking and breaking. Uh, I also like the kind of like building engineer in me really likes building systems. And so I really like, like working, working as the security engineer on an, an engineering team where there's a hardware guy, there's a firmware guy, I'm a kennel person. Uh, I mean, I really like, and I think that's, you know, so some of our clients are really kind of more longer term engagements where they're doing kind of this development. And then, um, you know, occasionally we'll do the, like, they've made the product. Let's do the assessment. Um, you know, see if there's any security problems, but I, but I really like getting in there early in the design phase and helping them pick the components, you know, you know, especially on the hardware side, uh, kind of like if you get the, if you don't get some of the hardware security stuff, right. There's only so much software can do. Right.
Josh Datko: Exactly. You've, you've written firmware for a part that doesn't have like a crypto core in it and you're like, okay, well, I guess we could do this all in software or in firmware, but that's not the best place to do it. So.
Dave Jones: Right. And so if, yeah. And so if you're like, well, you know, it, you know, that may, so again, the auto security is like, is, you know, is that a problem? You know, if no one can ever get hands on to the device because there's a Marine station 24 seven with a, an M four. And every time you try to touch the device, you know, he butts you with a rifle, physical access is not necessarily a problem. Right. Right. Um, but, uh, so then, you know, maybe you make some different design choices, but if this is like a Bitcoin harder wallet and people, you know, have it in their hands and they can lose it or they can be stolen. Yeah. There's some, there's some different, uh, design requirements there.
Josh Datko: Do you know people that carry that? I, I don't, I don't, I've avoided all the crypto cryptocurrency stuff. Uh, but do you know people that carry those around?
Dave Jones: Yeah. So, so Dimitri, uh, so one of Dimitri's like funny things to do is I, he'll go to conferences. He'll go to a cryptocurrency conference and he'll be talking to someone who's like, yeah, you know, like, you know, do crypto. Yeah. Yeah. Yeah. And he's like, Hey, did you leave your wallet in your hotel room? Right. And you'll just watch their face. He just watches their face go white. Right. Cause they realize like who they're talking to and they're like, oh, okay. Right. So it's like, uh, yeah. I mean, so this is some of the things that we're kind of probing at. Um, yeah.
Josh Datko: Yeah. So like just kind of cultural things as the culture builds up, even though it's a ridiculous culture. I mean, I made a little bit of a judgment there myself.
Dave Jones: No, I mean there it's, I have, I mean, uh, so I am fascinated. I mean, it is kind of intrigued. I guess I'm very intrigued by cryptocurrency. So, like I said, I had this background in act and like when crypto actually used to stand for cryptography, uh, uh, I mean, I had a background in that. And so I'm interested in cryptography, uh, you know, Bitcoin came out and I was like, well, this is like kind of an interesting, I mean, so there is a, there is an actual computer science problem that it was solving. Uh, and I was like, oh, this is interesting. You know, I kind of was, and then I was into a tour and some of these kind of decentralized systems. So I've been interested in the technology aspect, but then as it kind of like blew up, there's just this whole other, whole other world around it. Uh, which is interesting for more, um, uh, like people watching and, uh, the culture. Yeah. Yeah.
Josh Datko: Which is develops.
Dave Jones: Yeah. And so that, I mean, it's very intriguing. Um, I, uh, yeah, I mean, I think it's like any, any technology thing though, right?
Josh Datko: Like the technology is interesting in the beginning and then it gets used for something, right? Yeah. So you could say the VHS Betamax kind of thing, right? So like tape recorders are very interesting machines. However, the money was not in the guts of the machine or even making the machines. It was in the content that went on the, the tapes and the.
Dave Jones: Yes. Yeah. Right.
Josh Datko: Sometimes loop content that really drove the VHS versus Betamax stuff. Right.
Dave Jones: Right. Right. Yeah. So it like, uh, I mean, so I, I mean, I go, I mean, I, like I said, I have clients who work in there. I mean, I, I, uh, you know, I have done these talks, everything. I mean, and so I am, there is a part of me who's like intrigued by this. Um, but yeah, like I've gone, there was like Wyoming. So here's an example. So like, uh, I was at the Wyoming, uh, there was a Wyoming had a block blockchain hackathon. And so I live in Colorado and Fort, and Fort Collins is not too far from Laramie, Wyoming where they have this thing. It's not that close though. Oh yeah. I mean, it's a few drive, but like, I mean, it's the next state over, um, you know, and Wyoming, Wyoming kind of has this like, you know, cool, like a Western kind of feel to it. So like, I always kind of go to Wyoming, the wife, uh, doesn't like going so much because she complains there's not much to do up there, but you know, it's, uh, it's fun. So, uh, I go to this blockchain hackathon and, uh, you know, Wyoming's trying to pass all these laws and trying to be this adequate, adequate for blockchain companies. And so they have this, uh, example. So, you know, they're all, you know, they have lots of sponsors. And, uh, one of the things that they were talking about was, um, beef chain, right? So Wyoming is about Wyoming and you're like, so part of this, so a lot of, a lot of, so a lot of this is, it's like, kind of like what I was talking about in the military, like being in this thing and kind of being able to like step back and then just realize some of the ridiculous things that are going on. And then I can't help it. And mess with it. Right. And so like, uh, so, okay. So, so I'm going to try to say beef chain without cracking up about, um, so they have beef chain. And so, you know, so there is a hint of a pro an actual problem here. And so what, uh, you know, so they had the problem if that, you know, they've got this cattle and the Wyoming ranchers really want to make sure that the Wyoming cattle is appropriately, uh, like tracked as it goes through the process. Right. So they added, uh, you know, they're like, Hey, let's add RFID tags, uh, to the cattle. And so they, you know, they have this RFID system, you know, this is all, there's no blockchain yet, right. They just add RFID. They track the cattle as it goes through. And they had all these great, uh, the meat processing again, I think I was the only person cracking up as this went in, as it's like a very serious lecture has been given, but they had all these great euphemisms for like, you know, how they actually, like, you know, I, hopefully if there's any listeners who are sensitive to animal stuff, but, um, like how they actually slaughter the animals. And so they, it's, it's the product, right? Like they're, the product is being transformed, right? It's all these like great euphemisms, right? Yeah. So, um, right.
Josh Datko: So the, uh, make it more like sanitized and like, yeah. Right. So I mean, it sounds almost.
Dave Jones: Yes. Right. I mean, there's, it's, the product is going through the process and it gets transformed, uh, and all right. So it's basically going to the slaughterhouse. And so, um, so any, so the cattle comes in, what the ranchers want to do is they want to tag the cattle when it goes through the processing facility. Um, they want to make sure there's continuity of like, Hey, this meat essentially came from this cattle, which was on this ranch and this ranch, it was a grass fed ranch and all this stuff. And so, so I mean, okay, so there's a legitimate, you know, business concern here and there's like, right.
Josh Datko: And what they used to do is they would do branding and then they did barcodes and then they did RFID and right. They, it's just technology has followed the same problem, but now they're applying a new technology to it.
Dave Jones: Right. So, but like, I mean, so then, so, so I mean, the way I was reading into this talk is that like, okay, they wanted to do this thing, but like, no one was really getting super excited about it. Cause like they would have to build this like database, um, you know, they'd have to build like this traditional database and tracking and like, you know, okay. Like you, you went from branding to RFID, but no one really got really excited about it. But I'm pretty sure what happened is what one day some guy was like, Hey, if we put this thing on the blockchain, we might be able to raise money for this thing. Right. So they're like, right. So I can just imagine some meeting where they're like, oh yeah, yeah, yeah. Let's do that. Yeah. Okay. Cause basically, I mean, basically.
Josh Datko: And we can find coders that want to work on it. Right.
Dave Jones: Right. Yeah. Like this is going to be like, so how do we do this? What do we, okay. What do we call this thing? Like, okay, well, we've got beef and we've got blockchain. Well, let's call it beef chain. Right. And so, so beef chain was born and it's that same process that I just described. And then basically they're just, instead of putting it into a traditional database, they're putting it on the blockchain. I mean, but now it's sexy and there's people who want to, you know, develop, you know, there's software programmers who want to work on it and it gets attention and it gets newspaper articles. And I mean, so from a like marketing point of view, I mean, they're kind of onto something. Sure. Yeah.
Josh Datko: I think it's totally a marketing term. It's just like IOT was 10 years ago. Right. Yeah. Even though there was actually people doing connected devices much before that, it's just Yeah. The way that these hypes go.
Dave Jones: Right. M to M, right. Like machine to machine. Yes. Right. Right. Of course. Which apparently just IOT because you capitalize the first and end letter. And I think that's what makes a successful acronym.
Josh Datko: That's how you raise money. That's right.
Dave Jones: That's it. That's it. So, so yeah, so it is, I mean, there is a lot of, yeah, I mean, I don't think.
Josh Datko: Observe the ridiculousness from outside you're saying, but you also benefit a little bit.
Dave Jones: Yes. Yeah. And I think, I mean, even in security, I mean, I mean, it's not just, I mean, it is a little more in blockchain stuff, but like I pretty much in everything I did, like in the Navy and in Afghanistan, I don't know if it's time for another story. Should I do another? I think so. Yeah.
Josh Datko: I think, I think maybe we should end on a couple of stories and then, and then, and then cut it off. But at this point, if people are listening past beef chain, they probably were saying it for the stories.
Dave Jones: Yeah. Right. Right. Yeah. That's true. Yeah. Okay. So let me, let me look at my, let me look at my list here to see. Okay. So they, um, yeah.
Josh Datko: Any Afghanistan stories?
Dave Jones: Yeah. So, okay. So yeah. Afghanistan. Okay. So the reason I was in Afghanistan is itself just odd. Like it's very much a Joseph Heller. Able officer. Yeah. A submarine officer. So I was working, so I was in the reserve. So I was in a civilian job and then they recalled me. Right. So they're like, Hey, you, you, uh, you, you are of enough importance to national security and this thing that we have to pluck you from your civilian job and you're going to go over and fight in the war. Like, Oh man. Okay. Well, oof. Okay. You know, how long am I going to be there? Are you going to be there a year and a half? I was like, Oh, that's, that's a long time. And they're like, well, you know, what am I, what am I going to do? And they're like, yeah, your orders say you're going to show up at this base. We don't actually know what you do. Like there's some number. So I didn't even know what I was going to do. And I'm like, Oh, okay. Uh, so, so like I get the orders and I get mobilized and I go to, you know, I start to do the training, which was to go, I went to, we did somewhere in Georgia and we did like army for Navy officers. And so like you, you do a whole bunch of shooting.
Josh Datko: Okay. Like a basic bootcamp kind of thingy, but basically learning how to do it on land.
Dave Jones: Right. So the, basically, I think it's the idea that like, if you happen to be, so, I mean, like, like basically the idea is, uh, you, the Navy office, Navy and air force personnel go into the kind of like a combat support role. So basically the desk jobs so that the army people, you know, the army personnel can actually go and do like what they're the war fighting. Right. And so this is for whatever reason, you know, I am convinced probably there's some like budget reason, like they couldn't get more army personnel. And so if someone was like, well, we'll just send Navy people. Yeah. Right. And then we'll staff them and then everything will work out great. And, uh, so, yeah, so I get sent over there and then, you know, I'm in the training in Georgia and they're like, Oh, you know, uh, Lieutenant TACO. Oh yeah. You're going to need an M. So typically just the officers get a pistol, which is the M nine Beretta. And so they're like, Oh yeah. Daco, you're, you, you need a M four, uh, which is the AR 15. You still don't know what you're doing.
Josh Datko: And basically I'm doing this big weapon now.
Dave Jones: Yeah. But all of a sudden they're like, yeah, you, you need, you need this M four. And it's like, I'm like, why do I, why everyone else just needs a pistol? Why do I need to? And I'm like, I mean, they're like, Oh yeah. Cause you're like, you're going to be going outside the wire, which means like you're going to be going out outside the base and doing missions out in Afghanistan. And so I'm like a Navy submarine officer. I'm like, uh, okay. Uh, like I know it, like I learned something today. Yeah. It was like, this is okay. So then I like, okay. So I did all the shooting stuff and passed all that. And then I get, you know, so I still don't know what I'm doing. So I just get told, like, show up in Afghanistan, go to this guy, meet him. And then he'll tell you what you're doing. I'm like, okay. So I go over there, uh, Bagram air force base and I meet this person and they're like, yeah, Lieutenant Datko. Uh, we don't actually have any record of why you're here. Like, do you know why you're here? I'm like, what are you talking about? I'm like, you, what do you, I'm like, I've got these orders. Uh, you know, I had like the civilian life. Like you, I'm like you, I spent the last month like learning how to fire all these weapons. Like, what do you mean? There's no record. And they're like, uh, I think I'm a spy now actually. Right. They're like, well, you know, like, well, you know, what's your background? Like, yeah, like I do this, you know, like, I do like a program. I do like embedded software, like electronics. I'm like, okay. Yeah. Yeah. Okay. Go, go talk to this guy. I'm like, okay. So I go talk to, like, I show up and I go to this building, right? I'm like, walk in. I'm like, and I'm like, uh, I was told to check in here. I'm the new guy. I'm like, oh, uh, okay. Uh, so I was working with this group called the joint. Uh, so it was J crew, which is an acronym within an acronym. So let me see if I can decompose all the acronyms. So it's joint counter IED, which is improvised explosive device, radio electronic warfare or something that basically is jammers. Uh, so, so you can imagine.
Josh Datko: So you're out driving and you don't want to have like remotely detonated thing. Exactly. Exactly. So you say all of the energy in the spectrum so that we can drive through hopefully safely.
Speaker ?: Yeah.
Dave Jones: Right. And so that's, and so like, you know, they're like, oh, you seem to know something in electronics. Why don't you go work with these jammer guys? And so I was like, okay. So I go over there. Um, but it was, again, it was just like this situation. I mean, so I was in this old, you know, we're on Bagram air force base and it was an old Russian building. Um, you know, cause the Russians were there way before us. And then like none of the doors, like every, every, like it was like four feet country concrete. None of the doors like ever closed. Cause they're all like bespoke. Someone just poured concrete and the, and, um, you know, it was on this base, but the base, like there was more civilians walking around than, and the military, right? So like I would be on Bagram. I'd wake up, I'd go get coffee at like, there was a KFC. There was like, and I'm like, this is different than my submarine experience. Like, uh, I mean, I could get on the internet. I could, and it was just, it was just odd. And then, you know, occasionally there'd be a couple of mortar attacks. I mean, so the base, so I would, you know, I was a submarine officer. There's a reason I picked submarines and not Marines. Right. So like, I never wanted, you know, no desire to go, you know, so like people would come in and they're like, Hey, Lieutenant, you want to go on the convoy down to this fob, which is a forward operating base. I'm like, no, like, Oh, you can just ride on. You can just ride along. I'm like, I know I'm, I'm quite, I'm okay. Like, I don't need to, I don't need that excitement in my life. Right. Right. So, um, so it was just weird. And so like, you know, there's, I, you know, they're going to get mortared, uh, and like, you know, occasionally mortars would land on, on, uh, you know, a bunch of people and kill a bunch of people and stuff. But like, otherwise it was pretty safe. I mean, on the base. Yeah. So, but like, like, again, like I can't, like, I'm just in that situation and like, I, it's just, I find this ridiculousness. So there is this, uh, so there, there was this guy, um, and he was this air force guy and he, you know, a very serious kind of person. He's like, you know, like, like you would, most military people, you know, like filed orders and stuff. And, um, you know, as you would expect most military people to do. So he's a very serious guy. And, uh, you know, one, one night, uh, it was somehow they were doing construction, like right next to where I, so I worked like, I don't know, 30 feet from like the barracks I was in and, but they were doing construction or something. And so we had to be rerouted to walk around into this other area. And there was like, it was like poorly lit and there was like gravel and it was just kind of like a spooky area to walk back around. And so I had got the idea like, oh man, when this guy, when this guy walks back, I'm going to sneak up. Oh boy. Right. I'm going to scare him. Yeah. And so, so I, you know, like I do jump out and get them. And, uh, and then I realized like, actually we're both wearing loaded pistols, right? Yeah. Yeah. That's exactly what I was thinking. This is not safe. So I had like waited for him to go by and then I just like jumped out, like scared him. And I was like, oh, this, this could go bad actually. So bad. But he, I mean, his face went completely pale. Um, so that was funny. So the, so then another one is like, uh, you know, waiting in line.
Josh Datko: Do you still, do you still tempt death like this? Is this like you like, oh, look, there's a, there's a, there's a beef chain bull over there in that field. I'm going to go wave a red flag in front of it.
Dave Jones: I think, I think this is kind of how I got into security a little bit. Cause it's like, you know, a lot of things is just probing things and like trying to do things that you're really not supposed to do it. Like, oh, like, oh, why, you know, like, well, who says I can't like open this thing?
Josh Datko: Maybe I should unlock this thing. Maybe I should try and hack this thing. Right.
Dave Jones: Right. So a lot of, I think it just comes from being like curious and just like prodding. So like, um, there was another one. Uh, so like we're waiting. So you have to, you know, you have to eat in these dining facilities. Um, so they're called defects where you eat it. Everyone goes to eat. And there was the sign. And I remember seeing the sign and I was like, and then the sign said something like, no, no shirt, no shoes, no gun, no service. And I was like, oh man, I really, I should take a picture of the sign. Cause they're like, there's so many people who would love, love the sign. Right. And I, you know, I think I made that comment out loud where this guy, you know, he, uh, uh, you know, so basically the idea is that you're supposed to carry your weapon with you all the time. Like they, they used to have a rule where you don't carry it. And then now they changed it. So they made these signs. Well, this guy turns around and he's like, oh, sir, don't worry about it. You know, if you forget your gun, uh, you just tell them you're a chaplain. So chaplains by like military law aren't allowed to carry weapons. Right. So you don't want like a priest out there going around, you know, maybe a little bit of conflict of religious interest if the priest, uh, you know, is on the front line. Maybe. So, so it's like, he's like, sir, just tell them you're a chaplain or just tell them you're on suicide watch. And then they won't ask you any questions. Right. And so I was just like, oh my goodness. Yeah. So, uh, yeah. Um, this is, this is the kind of environment that was going on over there.
Josh Datko: Well, Josh, I'm, I have to say, I'm glad you're back in civilian life. It sounds like a military life did not suit you all that well. Although I'm glad you made it. You made it.
Dave Jones: Yeah. I made it. I made it out. Yeah. Right.
Josh Datko: Uh, where can, where can people find out more about you and maybe more about your talk that's coming up?
Dave Jones: Yeah. So if they go to cryptotronics.com, uh, which is my company's website, I have a blog post there that talks about the upcoming, uh, CCC talk. Uh, so it's, I think it's right on the front page and, um, you can go, uh, look and see the other CCC talks and kind of get some more information. And the talk is, there's also a website for the talk called wallet.fail. Uh, so Dimitri, uh, Dimitri got that domain name. Uh, so if you just go to wallet.fail, you'll, you'll go directly to that. Um, yeah, but yeah, cryptotronics.com has, has the links to more about us and some of the other, other, the actual stuff we do besides some of the, uh, the fun antics.
Josh Datko: Got it. Any, any social medias for you?
Dave Jones: Yeah, I am. I mean, I am on Twitter. I have crypto TX. Uh, I have like a love hate with Twitter. Um, so yeah, so I, I don't post all that often there and I think I'm on LinkedIn. Yeah. So I'm on LinkedIn, whatever that URL is like slash Josh, Josh.co. So if you do the custom one, but yeah, all this is from the main, if you remember cryptotronics.com and then I have a personal blog, which I haven't logged out in a while, but .co.net. Um, I read, uh, 60 something books last year. And so if you want to see what books I read, uh, you can go to tatco.net. Oh, nice. Get some book recommendations.
Josh Datko: Yeah, that's great. Especially as the holiday season comes up, that's good for finding, finding books to read. Yeah.
Dave Jones: And they all should be, uh, they all should be in paperback now. So they'll be even cheaper. Nice.
Josh Datko: Well, Josh, thanks for joining us and thank you for telling your stories. I'm, I'm glad to hear them again. And I'm sure there's even more the next time we grab a drink together.
Dave Jones: Yeah. Well, it was a pleasure, Chris.
Chris Gammell: Great. All right. Thanks a lot. Yep.
Dave Jones: Later.
Speaker ?: Bye.
Archived Discussion (1)
Comments are closed. Archived from the original site.
Show archived discussion (1)Hide discussion
- benWow, 70 books a year?! Looking at the list (datko.net).. they seem mostly fiction? Any stand-outs?
blockchainCryptographyembeddedmilitary contractorNavyNuclear reactoropsecSecuritySubmarineTor
Keep current
Every episode, plus the occasional job post, in your inbox.
