#575 – New Life Skills with Joe Grand

01:04:27
New Life Skills with Joe Grand cover art

Download episode · 62 MB

Also on Apple · Spotify · YouTube · RSS

Show Notes

Welcome back, Joe Grand!

Transcript

Chris Gammell: This is The Amp Hour Podcast. Released January 30th, 2022. Episode 575. New life skills with Joe Grand. Welcome to the Amp Hour. I'm Chris Gammell of Contextual Electronics.

Joe Grand: And I am Joe Grand, a hardware hacker and engineer. Welcome back, Joe Grand. Hey, thanks a lot for having me. It's been, what, 10 years almost? 10 years, yeah.

Chris Gammell: You said that, I was like, no, that can't possibly be. That's crazy. I mean, it's been. But Joe Grand, episode 60 of the Amp Hour. So people want to, we will obviously link that in here, and we'll be referencing that. But episode 60, what the hell, man? That was a long time ago.

Joe Grand: A lot has happened since then. What, 515 episodes ago? I mean, that's, yeah, that's crazy. It's amazing that you've been able to continue doing this for so long. And I guess that we're able to still do engineering and all of the stuff that we like still.

Chris Gammell: I mean, well, so, you know, there was like the show. We read episode 60. Then there was like eight years. And then there was the past two years, and that was about 1,000 years. So it's been like, you know, that 1,000 plus years that have been here. So yeah, I mean, and we're getting through it. So we're getting there. Well, yeah, thanks again for having me. What have you been up to in those 1,000 years between now and then? Getting older, that's for sure.

Joe Grand: Well, let's see. I guess the major things is we were in, so we lived in San Francisco at the time. We like kind of wrapped up prototype this. And I was just doing some engineering consulting work. So working on a couple products on a consulting basis. And geez, yeah, ended up having a second kid. When our kids got old enough to go to school, we're like, well, San Francisco is really expensive, especially as an independent engineer. So we moved up to Portland, Oregon, and kind of settled down here. And yeah, it's been great. I've been doing a lot of hardware hacking training, which I was doing back then, but not as much. So a lot of, you know, traveling on site to organizations to help them understand, either help their engineers understand, you know, how hackers are looking at their products or help companies that need to analyze products, how to do that.

Chris Gammell: Yeah.

Joe Grand: So it's been really satisfying and still doing a couple electronics designs here and there, but mostly kind of focusing on the hacking and software or security side and trying to share as much information as I can, you know, through my videos and stuff, which I don't make very often, but once in a while.

Chris Gammell: I think that's why it feels like, you know, like we've, it's crazy it's been 10 years because I see you at a lot of, well, back when there were conferences, you know, like, and we've had many people on the show since then who are in a similar space through to do a lot of the same training, like Colin O'Flynn and Joe Fitz and Josh Datko and who else we had? Dimitri's been on the show. And, you know, so just we've had a lot of people in this space. Yeah. I've been on the show that are doing a lot of this, you know, similar things, not, not saying things, obviously all have different areas. And it, it's interesting to me, you know, I've talked to those guys about it. I mentioned it here again, you know, the, the companies that are hiring people like yourself, like, could you give us a refresher on the types of companies? We don't need any specific names, but like who, who is, who is worried about this sort of stuff? It, it ranges.

Joe Grand: It is really more, at least for, for my work. And I don't know if it's just because I'm in this sort of recurring kind of educational curriculum curriculum for these organizations. But yeah, a lot of sort of, I would say government related organizations as opposed to private sector, right? So it, got it, got it. Okay. The private sector organizations, I'll do trainings once in a while. And it's mostly, again, mostly for engineers, sometimes for security professionals who are doing consulting work and want to learn, want to learn more about how to approach hacking a piece of hardware. And it really is, my stuff starts out at this really basic level because that's kind of where I really like seeing the growth of, you know, people coming into class. And a lot of times too, it's not even engineers. It's, it might not even be a technical group, but seeing them kind of go from looking at the hardware that we're working on and kind of, you know, being like, what is this to over the course of two days or however many days I do it, you know, have a soldering iron to it and a logic analyzer to it and, and, and monitoring traces and cutting or monitoring signals and cutting traces and all of these things, you know, kind of basic hardware hacking skills, watching them reverse engineer a board and defeat security of something is, is totally satisfying. So I like that kind of aspect of opening up this world to people, even though, you know, no class is going to make anybody an expert, but to introduce as much as you can to them and then let them go off and do it on their own. Like that's so satisfying to, to see. So that's really, yeah.

Chris Gammell: Yeah. It's like bringing, bringing down walls and, you know, making it less intimidating, I feel like is, is a huge step. I mean, I feel that on the firm, I mean, honestly on firmware side, like when I have people helping me with firmware, I'm like, oh, you know, I feel like I can do this, you know, there's still going to be struggle there. It's still going to be, you know, you're going to have to dig in and do your homework and yeah, like have, have a good rigorous method, but like, but it's still that first step is really important.

Joe Grand: Yeah. And you know, there's so many different aspects you can get into, whether you want to, you know, hack on hardware or hack on firmware or software and with embedded systems, it's kind of a combination of, of everything. Right. So you kind of dip your toe in the water of all of these things. And really what, what I try to impart on people is, you know, a lot of the stuff we can do is using standard engineering tools. So we're using our scopes and our logic analyzers, power supplies, device programmers, all of these things that we as engineers would use for development anyway, you know, debug interfaces, whatever. And they're using those same things. So I, I try to get them to kind of either put themselves in the mindset of the engineer, or if they're an engineer, put themselves in the mindset of the hacker. And like, what's the, how can the hacker use these interfaces that are helpful to me against me? And once they get over that hurdle, that's, that's really the thing. So it's, it's trying to dispel this notion that hardware is hard. I mean, it is, but it's not insurmountable, right? It's like you can get, if, if you, if somebody can point you in the right direction, I think that's, that's the hardest part is like getting that first step of, of knowing where to go and what to do.

Chris Gammell: Yeah. Well, another thing we talked about before the show that since the last time you've been on, you actually released a product back in 2013. So that was, it's been a while as well, but that is a tool that also makes it more accessible and it's called the J tagulator.

Joe Grand: Yeah. So, so that tool is essentially a tool to help you identify the function of unknown test points or pinouts or say an unpopulated connector on a circuit board. And the intent there kind of came out of my hardware hacking classes where I talk about how to look at a board, you find test points, you find whatever and you need to trace them out to a microcontroller or trace them out where they go on the board. And then what to do once you found that. So say you identify some pins, you think it might be a J tag interface and then you can go and do something to exploit that J tag interface or take advantage of that or you are or SWD. Whatever it is. So the J tagulator kind of bridged that gap between visually seeing those interfaces on the board and then doing something with them. And I originally created that. Yeah. 2013, I made a hundred of them on my own to sell at DEF CON and I gave a talk at DEF CON and a talk at Black Hat about it. And really, I didn't think anything of it. I didn't think it was going to, you know, be a thing, but it turns out that it's still, still around, still kicking, fully open source. We use a propeller microcontroller, which, you know, I'm sure you've talked about on the show in the past, but a very unique kind of very unique core microprocessor. And sometimes I regret using that compared to like a more standard type of device because I think I'd have more community contributions if it wasn't such an arcane kind of thing. But the project kind of turned into this actual product that I had to support and add new features and all of these things. So, yeah, it's kind of become one of these tools that's worth having in your toolbox. And, of course, some people say, well, it's so expensive because there's a lot of costs that go into manufacturing and that's the beauty of the open source stuff is all, you know, all the files are online. Gerber plots, go make your own. You can assemble your own if you can actually find components these days and use it. So, it's just one of these handy tools to have. I'm at the point where I've kind of frozen the firmware. I'll make bug fixes if I have to, but I'm not planning on adding any more features. There are some really cool features in it that aren't just to identify debug interfaces. So, one in particular I just did as kind of one of the final features is, I call it the X-test scan. And that one will help you identify the physical pins on the chip and how they correspond to the actual boundary scan register inside the chip. So, as far as the position of the bit inside of the boundary scan register. So, that's more of kind of an advanced probing tool, but it also is handy from an engineering perspective. So, that's something I thought was kind of fun. But really, the core purpose, oh, it also has support for OpenOCD. So, once you discover an interface, you can use the same tool. But it's really slow. It's not really designed to be a multifunction printer. It's just, it originally was designed to find these interfaces and then some of these other bonus features will work. But really, once you find the interface, you'll want to end up using proper, faster, better tools. Get a J-Link

Chris Gammell: or something. Yeah,

Joe Grand: get a J-Link to do that stuff. But yeah, you know, it's funny that it just, and it's great to see that it actually has still been of interest. And I thought it was just going to be hackers that were interested in it. But engineers buy it also because they can use it to make sure that their interfaces are actually inaccessible, right? They can do their development, they can lock down JTAG and then see if the JTAGulator can still detect it. Yeah, just a cool tool to have and that was, that was something.

Chris Gammell: Well, plus it also has the signature pink, pink color. So I think that also makes it easy to notice out in the wild. That's right. The pink, yeah, the pink board.

Joe Grand: That was one of the first pink engineering tools. I'm not sure. Maybe. But yeah, so, you know, it was a fun, fun project and still kicking.

Chris Gammell: That's great. That's great. So, so if people are interested in contributing, they should reach out or maybe.

Joe Grand: if you go, if you go to JTAGulator.com, that just redirects to my, my website, but then also on GitHub, just search for JTAGulator and you'll see the main, main repo there. Yeah. Yeah.

Chris Gammell: Well, we had also talked about another, obviously, you know, so, so Joe and I were talking before we started recording and I was like, well, you know, we've been talking about you for the past 10 years. It's just, we haven't been talking to you on the show. My ears have been burning. That's right. That's right. But another thing we mentioned was the DEF CON badge you did. So you, you made a glorious return in a DEF CON badge where you had a, they were all stone. Yes. Polished stone badges at DEF CON. They were very cool. I think we mentioned those on here.

Joe Grand: Yeah. So there's actually, so I'm looking at the show notes from episode 60 and we talked about the early DEF CON badges. So 14 through 18 were the first electronic badges that we know of for conferences. And after DEF CON 18, I'd gotten to the point of like, well, I feel like I've kind of served my purpose. You know, badge life wasn't quite a thing yet, but people were starting to make their own badges. It was becoming, it was the beginning of badge life. The beginning. Yeah. And people, and people had become, they were kind of expecting me to do an electronic badge and my personality, at least at the time, was like, well, if they're expecting me to do it, I'm not going to do it. Oh man. He's like,

Chris Gammell: he's going to change his name next. The artist formerly known as Joe Grand.

Joe Grand: That's right. But I just kind of got tired. Really, it was, I was tired of kind of competing with myself to try to do something better each year. And it was a huge amount of work. So at that point, I'm like, I'm retired. I'm never doing it again. And that lasted for a pretty long time. But then, yeah, nine years later. But then there's always

Chris Gammell: the comeback tour, folks. Come on. You got to have,

Joe Grand: which I don't recommend.

Chris Gammell: Just quit while you're ahead and stay that way. When you're older and more easily tired and then you're like, yeah, I should do a comeback tour.

Joe Grand: Yeah. And well, so this was actually a comeback tour times two because I met with the Dark Tangent who runs Defcon. Runs Defcon. He was actually organizing a Defcon China event. So we were talking and he's like, hey, so I'm doing Defcon China. You know, it's more low key. There's only 3000 people. It would be cool to do an electronic badge. And I'm like, oh, I don't really, you know, I don't really want to do it. But the timing just happened to be that I've been traveling a lot, teaching a lot, like sometimes even multiple weeks out of the month. And I was just kind of burnt out from traveling. So talking to my family, they're like, yeah, why don't you just do another design? And then you'll be home a lot more. I'm like, okay, that sounds cool. So the Dark Tangent, Jeff Moss, basically convinced me to do the Defcon China badge. And we right away, you know, figured out an idea and we're riffing off it and came up with a really cool concept. And then towards the end of that visit, I went up to Seattle to see him. He's like, so what about doing Defcon 27 as well? which is the same year. And, you know, we've known each other for a really long time, like since, since we were teenagers and I love him. He's a great guy and very, he just so influential in the community and what he provides and just his insight. And he's the one that actually got me to do hardware hacking training back in 2005 when I started when he was running Black Hat. So he kind of has this vision that I don't have. So I'm like, fine, okay.

Chris Gammell: What I'm, what I'm imagining you're going to say next is, but when he suggested that, I punched him right in the nose.

Joe Grand: No, I was like, oh, I don't know. Fine. Like, let's do something crazy. And, and then, so I basically agreed to doing two badge designs in the same year. And yes, my family was right that I was home a lot more, but it ended up being like, you know, 80, 80, 90 hour weeks or whatever. I mean, it was a lot of work. Yeah. And mostly because it was just me working with some of the, the Defcon staff and Jeff, but it had to be a secret. Right. And it's so much more fun when you have this collaborative effort and you can like bounce ideas off of other people or other technical people or share design, you know, pieces. And how does this work? And I worked with some of the, some of the engineering, you know, the, the, the FAEs from some of the companies, they were like my only sounding board for things. But yeah, so Defcon China ended up being a flexible circuit board. This one, I really loved. This was one of my favorite designs. Uh, cause I'd never worked with flex before. So I'm like, well, if I'm going to work with flex and someone else is paying, this is a perfect time to do it. Yeah. As long as you get multiple spins. That's, that's the, that's the next little sentence. I believe though. Multiple spins. Yeah. Well that, that one actually, we didn't really have time there. We had one spin. Oh my God. Which was, which was nuts. And, um, not recommended. So, you know,

Chris Gammell: with the tree, the tree looking one, is that the, yeah,

Joe Grand: so that's a tree. So basically the concept was you have a, it's like a tree looking badge different stations around Defcon. You know, you'd go to a talk, you'd go to a village, you'd participate in different contests. And people had these little devices that I made. You'd plug in the badge through a flex. Connector and FFC connector. And it would. Send some data and then enable the lights. So you had all these different routes. And as you completed the different tasks, the routes would light up. And then when you eventually. Completed all of the tasks, you get some blinky light action and stuff on the badge. So it kind of was a way to introduce the, the, the Defcon China audience, which was not as established of, of like what to do at a hacker conference, kind of expose them to all of the different things and have fun with it. And I had a little workshop on how to, on how to, you know, hack the badge and modify it and stuff. And it was actually my first. Actual Arduino based design. And my last since then, I haven't had another reason to use it, but it was actually cool. I ended up doing some really low power stuff on it. And a friend of mine still has a badge. It came out in may, 2019 still has a badge that works with the same battery, which is, which is kind of cool, but there's some like motion sensing on it and some other stuff. So that one was really fun. And it actually came together pretty well. What I would recommend is if you are working on flex, obviously don't, you know, don't just do one spin. So we had the prototypes made and there was one, I had the transistor pin out wrong for something. And I had to cut a trace, but cutting a trace on a flex board is hard, right? Because there was traces on the other side and the substrate was super thin. So it was like this total hack job to, to cut this trace just to make sure that I would, you know, that, that I could test everything and make it working. So that was the only change that I had to make on, on the main one, but it came out cool. We had different solder mask colors and stuff like that on there. Yeah. And then at the same time I was doing DEF CON 27, that was more of a struggle because we wanted to do something different. And I'm always, you know, I'm less about like making a, a, a puzzle challenge. Like I just wanted people to enjoy using the badge. So everybody expected it was going to be this like complex challenge, you know, kind of CTF based with hidden puzzles and stuff. But like my mind doesn't work that way.

Chris Gammell: Sorry. We need to disambiguate for some of the audience here. CTF is capturing the flag. And there's often puzzles built into the badges, like Addy and Whisker often had, they had some very crazy follow on later designs that were very, very puzzly. Yes. Yeah, exactly. So yeah,

Joe Grand: basically hidden puzzles and you, you know, you solve different puzzles and get different pieces of data or flags and, and you complete your, your challenge that way. But I just wanted something that was a little more accessible and super clean, which is always kind of my aesthetic of trying to do stuff that just looks really kind of nice because of the 30,000 people that are at DEF CON, only a small percentage of them actually, you hack on the badge. That's right. Yeah. Yeah. So I didn't want it to be like this overwhelming thing where people were annoyed of wearing it, but at the same time I wanted to, to kind of mess around with stuff. So this one was a great opportunity for me to work with, with BGA, with ball grid array devices, micro BGA, actually. Yeah. I just wanted to do something that I'd never done before and maybe bit off a little too much for this, but essentially the concept was similar to DEF CON China, where you had to go around and complete different tasks at the event. But instead of using an FFC connector, we use a wireless communication, NFMI near field magnetic induction, which is normally used in like hearing aids to send data just, you know, between one hearing aid on one ear and one hearing aid on the other ear. That's right. But we're using it kind of as you can almost think about it as like active RFID, but it's not, it's magnetic induction. So kind of, you know, think about like an air core, an air core transformer. Yeah. So somewhat close range, not super far. I think it was like a couple of feet max,

Chris Gammell: not, not, uh, touching badge to badge as everyone was doing. No.

Joe Grand: And it's funny because when, when people got the badge, like I wrote a little description about it in the, in the DEF CON program, but you know, nobody really reads those things. And, uh, so when people, people heard it was magnetic induction, they thought it went magnetic. So they're actually physically touching them together. Like, you know, you'd hold two magnets together or something. And I'm like, Oh no, but it was fine. Cause if you're close, it works also, but it didn't have to touch. And, you know, they were like kissing badges. It was actually kind of funny to see, but yeah. So basically you go around and you unlock your different tasks as you go. And it really was just a, I call it the badge quest. So you had to go to a talk, go to, um, a village, which is like, uh, you know, kind of little conference within a conference, I guess you could say event. There's like a hardware hacking village and a soldering village and a lock picking village. So you go to a village and you would go to a party, go to a contest, kind of participate in all these different things around DEF CON. And as you did that, your, your badge quest would increase and the LEDs would change patterns to let you know what state you were. And then when you finish one, one thing you actually had to do is, is what I call group chat and find all of the different attendee types at DEF CON because there is the attendees, but then there's the speakers, the goons who are like the security staff, the press, and a bunch of other ones. So you had to find one of each person and all come together and hold your badges all together. And it does this like badge to multi-badge communication and then unlocks the final thing. So it really was trying to be this like communal challenge, but also individual challenge to try out different things at DEF CON, which was super fun. And all of the goons had the, the tokens that would be used to communicate, to unlock the different things. And that one, I wanted to look, we wanted to do something like the theme was very kind of airy and new agey. And I was like, what if we put like a, a gemstone on it? And I had no idea what I was getting into when I said that.

Chris Gammell: You're like, like guys, Joe moved to Portland. He's got this new lifestyle and he's,

Joe Grand: you know, well,

Chris Gammell: it's very wellness focused now. Well,

Joe Grand: down the street, there's actually like a gem shop. And that's what inspired me is like, we would go there all the time. We still do. I was like, what if I put one of the gems on the circuit board and then it would look so cool and it would hide all of the circuitry. So that's what I did. I ended up having to basically source. I had to learn about all the gemstones, figure out which ones are, are rely rugged enough to, to cut into thin. You know, pieces. And then I had to find a factory to do that. And that was a whole other story, but ended up finding a jewelry manufacturer in China that had a connection to Brazilian quartz, which is, you know, super common. So it's not like we were causing, you know, any sort of, any sort of problem there. And yeah, they hand cut 30,000 or 28,600, essentially circles, quarter inch thick circles. And then we had our local manufacturer here in Portland, who was doing all of the badges, have a process to use double-sided tape and stick those down. And it really looked like a cool piece of jewelry at the end. And that was kind of the hope is I was hoping it, you know, it would look cool, but then that people maybe would use it later on as a piece of jewelry. We had a little wristbands that you could wear that you could get and, and put it on as a watch and stuff. So it was kind of, it was a lot, like it was just a lot of features that I'm not sure everybody picked up on huge challenge from an engineering perspective with the BGA. And it was a four layer board and micro BGA, but super fun and, and really educational for me. But then at the same time, once the event happened, I, I, I didn't realize at the time, but afterwards I super burned out. Yeah. After the conference, you know, usually after black hat and Defcon, you're kind of worn out anyway, but this was coming home and I'm like, what am I doing with my life? You know, I just spent a year working on a badge for a four day conference. And every, you know, people wear it and use it or, or don't use it and sell it. And that's it, right? It was a lot of effort. I'm like, is this what I really want to be doing for the rest of my life? Stuck inside of a, of an office by myself. So I kind of had, I wouldn't say a midlife crisis, but I was definitely burned out. And then, you know, a couple of months later, COVID hit. And that really changed, changed my perspective on a lot of things, which we can get into, but you know, yeah, yeah.

Chris Gammell: I'm curious, I'm curious where you landed on this stuff. I mean, like I've, you know, sometimes I look up and I'm from, you know, my bench and I'm like, Oh, I'm making more electronics. Like, you know, it's not a, not an uncommon thought, you know, and it's like, is this having a good effect on the world? And I, I like to think yes, most of the time, but sometimes the answer is no. And it's like, okay, so where'd you, where'd you land on that, Joe? Yeah.

Joe Grand: So that sort of, that sort of thing is like, you know, my wife was like, well, it wasn't just, just the four day conference. Like people, people, you know, some people really got inspired by it and they liked it. And it's like, yeah, but then what also was a catalyst is there's a local surplus store here. And I was there because I like going there and just digging through junk. Cause I can't help myself. There was a box of a product.

Chris Gammell: And it's, and honestly, it's one of the, one, one of the few remaining ones I'm sure in the, in the country. Yeah.

Joe Grand: It's called surplus gizmos, especially now that weird stuff warehouse is closed. Yeah. In the Bay area.

Chris Gammell: A bunch of ones in the Bay area. Yeah. Bay area. Yeah. HLC or whatever it is. And yeah.

Joe Grand: Yeah. HSC too. But yeah, so surplus gizmos, they had a box of a, a product that I designed in around 2010. I don't, I'm not sure if we talked about on the show, but it was a, a, the first portable USB monitor. So you would, you know, plug it into a USB port of your laptop. And now you'd have a second monitor. So you can, you know, travel and have another monitor using a display link chip, not display port, but display link is a company that makes these USB display adapters. That was really fun. Good project. But I saw a box of those in the surplus store and I'm like, damn, this is another project that I spent a year of time working on. And it's, you know, and it's, this is where it ends up,

Chris Gammell: right?

Joe Grand: Yeah. And, and the guy at the store is like, I'll make, I'll make you a good deal on all of those. I'm like, no, I don't need them. And you know, I'm sure a lot of engineers have felt this because we're designing products that really are not designed to last forever. And you kind of have this product life cycle and, and things go obsolete or there's something cheaper or better, but it just hit me in a way. And maybe because I was getting older also, but it hit me in a way of like, what, what, what am I going to do? You know, I knew that I would always do something with engineering and hacking. Cause that's all I've ever done. And I love it. It was just that amount of effort. So when COVID hit, I basically stopped doing anything. I logged out of Twitter for like a couple of months. It was amazing. Healthy. Good. Yep. Watched a lot of TV, slept late, homeschooled the kids. And, uh, just kind of decompressed. And then little by little, I started tinkering with electronics again. It's like, Oh, I had this project idea I want to mess with. So I would just do it. And, and really try to get back to my roots of why I fell in love with electronics in the first place of being able to create something out of my own head that I want to do. Not that somebody else wants me to do. And hacking the same way. Like I wanted to hack on some stuff, but I'd always been too busy because I was traveling and, uh, or work designing something. And so I started hacking on some things again, not because somebody was expecting me to do it, but because I was genuinely interested in what the outcome was and the fun of doing it. So it took a while to get back into that. And I learned that I should just be a lot more selective in the, in, in the projects that I take on. And I also probably most importantly is I started meditating, which maybe sounds weird, especially because I go to that gem shop all the time. But it really is like, you know,

Chris Gammell: mental health. I mean, this is, yeah, this is the, I think this is a mental health thing. You know, there, there is also the, you know, new agey type of meditating, but no, I think, you know, it's a very healthy. Yeah, no,

Joe Grand: it is. And like the mental health aspect of it, I'd known for a while that I should be meditating. Cause you know, my mind is going a million miles a minute. And when, when, when COVID happened, it was perfect. But then really what happened also is I broke my foot on a trail run. And like my celebratory ain't like every year. I mean, I run all the time, but every year on my birthday, I go out on some trails and just go out, but I ended up breaking my foot on my birthday. So not only was it COVID, I couldn't get out of my chair. And I was listening to podcasts a lot, you know, lying down and letting the swelling go down. I'm like, now I should just start meditating instead. And that really helped me, you know, cause mental health is something we start to talk about in the, in the hacker world, especially, and maybe the engineering world as well. It's important. And you can't, you can't just burn yourself from both ends and, and expect to be happy doing what you're doing. Right. Totally. Yeah. And, and luckily, gratefully, I'm able to, to pick and choose what I want to do a little bit at this stage in my career, I guess you would say, when I understand that not a lot of people have that opportunity, but even just, you know, starting out, I was doing like five minutes of meditation a day. And I was like, this is really hard to even focus, just not on thinking, like just focus on my breathing or focus on what I'm hearing. And that just helped me kind of settle down a little bit and make me not get as, as stressed out. Every time I see a bunch of emails that I have to answer or just whatever, just basically be more present in what I'm doing and grateful for what I'm doing, but then also just realize like a lot of that pressure and that stress I'm putting on myself.

Chris Gammell: Yeah.

Joe Grand: So now I just try to get back to like the fun side of engineering and hacking. And I think that's, what's really helped me.

Chris Gammell: That's great. Yeah. And you, I mean, I think you've been doing some fun things here. So let's, I mean, if, I mean, if you're good to talk about these other things, I mean, it seems like you've, you've kind of found some more balance in general. So that's, that's great.

Joe Grand: Yes. Yeah. I think that's the right word. Balance is the right word. It's like, yeah. And you know, everybody wants to do so much and there, there's so many things. And I, I stopped. I also, the other thing too, is I'd never really, you know, I don't, I don't read a lot of internet. I actually don't read any internet comments. I don't really participate community wise online because I used to, as a kid for a long time and it tends to be just a lot more stressful than, than I, than I want to take on. Yeah. So I do miss out on some of those aspects, but that's why I love being in conferences or, you know, where I can hang out with people and talk and do all of these things. But I think there's, there's the only downside is like people are like,

Chris Gammell: Oh, didn't you see this thing on Twitter? I'm like, no, I post once in a while.

Joe Grand: I feel like on social media and maybe just in life in general, there's this overarching expectation. Like, Oh, Joe hasn't done a project in a while, you know, like, or, or, you know, what's Chris doing? You know, it's like, if you're not out there posting stuff, people just, I feel like there's this pressure that you have to do that. And I kind of gave up on that. It's like, whatever, if I have a project that's worth sharing, I'll share it. If I, if I'm doing something that is not worth sharing that people probably don't care about, I just won't, I won't share. And I won't put that, you know, put that pressure on me, but yeah, you know, it's just a balance.

Chris Gammell: That's what it is. People have been saying to me, Chris, stop sharing. They had, that's what they usually say to me is they're like, share less, Chris. No,

Joe Grand: no, you can never share. You can never share too much as long as you enjoy it. Yeah, that's true.

Chris Gammell: Well, uh, you have been, uh, you have since built a, uh, a thing called a pizza compass. What was a pizza compass? It does sound like it's right in the fun realm. Uh,

Joe Grand: that's exactly. Yeah. That. Okay.

Chris Gammell: So that,

Joe Grand: so this was something during COVID. So we were still locked down, but tests were just starting to become available. Yeah. You know, TV production was starting to happen again and everything. And, uh, I got a, I got an email from some people at wired and they're like, Hey, we, we want to make some videos about, you know, people building cool things, sort of like a miniature version of prototype. This where for, for people who aren't familiar, that was a show on discovery channel that I filmed back in 2006 to 2008. And it was for engineers building, you know, big, crazy prototypes of things. And we'd actually done some stuff as prototypes that have now become, you know, legitimate products from other people as far as like life-saving drones and the boxing giant boxing robots and self-driving cars and stuff. But it was, it was kind of a proving ground for concepts. So this was basically like,

Chris Gammell: and the, the subject of, uh, when you were on episode 60 as well, we talked about that in depth. So people can go and listen to that one as well.

Joe Grand: Oh, nice. Right. Okay. And, and that also a lot of the, a lot of the, the electronics designs from that show I put up on my website. So if you're curious of like that, you know, that process for that stuff, but yeah, so, so wired was like, Hey, we want to do something like prototype this, but shorter episodes. And this was at a time where, yeah, I was just kind of tinkering around with stuff. I wasn't really doing much, uh, wasn't traveling. And, uh, I was like, yeah, cool. That sounds fun. So I basically sent them a list of ideas that had been kicking around in my head for a long time. It kind of morphed into this thing, which is a, you know, device that you can be anywhere in the world. It has GPS. You push a button. It's going to locate where you are. It'll go over the internet, find the nearest pizza place. And then with a series of, of, of, you know, ring of LEDs, it's going to direct you to the pizza place. And it's kind of ridiculous. And, you know, in the video, I'm like, yeah, you could do it with a phone. Of course you could change the search, you know, search query to be where, whatever you want, but it was just a fun project that kind of incorporated a lot of things that I hadn't done before. And I love, you know, I love making videos. I'm just not that great at making them myself. So if you go on my YouTube channel, you know, a lot of them are focused on like how to use the J tagulator or some engineering, very, you know, engineering specific thing, but we wanted to do something here that was a little more accessible to show the engineering process. So for people outside of our world that can still watch this and be like, Oh, cool. You know, you can think of something and draw the block diagram and prototype it and get the boards made and build it and go out and use it. So kind of show that whole process with the trials and errors. And it was awesome. So much fun. And yeah, you got to watch the video. It's only, I think only 17 minutes, which I guess is long for internet time, but still, still worth watching. It was a lot of fun.

Chris Gammell: Yeah, that's great. That's great too. I mean, and it's interesting that like wired is like this big organization. I'm surprised that they were interested, you know, like building stuff. It takes a long time as you talked about, about with prototype this. And when you're on the show the last time, you know, and it's just like, I'm always impressed when media organizations are like, yeah, go build something because that, that there's a lot involved there. Like, you know, like the stuff you did and myth busters and other, you know, building type, you know, like I, I watched James Bruton's robot channel and like every week he's building another robot. It's just like, damn, like it's amazing. Every week he's, he's building more robots. It's just like, and it's, it's, there's a lot, there's so much more than just the filming process then. And, and there's usually a lot to the filming process too.

Joe Grand: Yeah. I mean, it's a huge amount of work and, you know, with prototype this, we had a lot of people helping us behind the scenes as far as runners and people getting the equipment that we needed and stuff, because, you know, it's hard. And I, you know, myth busters, the same thing, but this, you know, this is something where, yeah, you not only, not only have to be an engineer, you have to be the host and explain the engineering process, which I love doing. And this was something where I basically convinced them to, they, they wanted it done, I think in like a week or something. And I'm like, I was like, well, it's going to take three weeks because I'm going to need, you know, one week to, to prototype, test it all, maybe a couple of days to design the board one week to get fabbed and assembled. And then one week to fine tune stuff and then do the finale. And it really, it worked out really well. And because this was during COVID, we basically had, a cameraman come a local, local cameraman, which is now a friend of mine came and set up, you know, some really good cameras and lighting and stuff in my office. We did all the intro stuff about the project, you know, all of that. Then he left all the equipment there. So for the next two and a half weeks, every morning, the director who is in New York city would get on zoom and he would basically, you know, do the interview, the confessional style interview of like, okay, Joe, what are you working on today? And I would just, shoot my own stuff all day long. And they would end up cutting it together little by little. And then for the finale day, the camera guy came back and we did the finale and all the, all the closing stuff. And you know, the really nice shots of the compass. So it was a kind of hybrid way of production, which worked out. It was fun. You know, definitely. I felt like I was talking to my friends, you know, fellow engineers and stuff. And at that time I wasn't talking to anybody. So you can, you can actually even see like, as the days go on, it's like, I'm getting a little more crazy as I go, but it was really fun because I just, I felt like I was actually with people sharing my, which, which felt good.

Chris Gammell: Getting back into that. That's that actually like socializing with people. Yeah. Yeah.

Joe Grand: It was like in my imagination, I was socializing.

Chris Gammell: Well, and so then this, this camera person also led into you doing your most recent video, which is, you know, what had me reaching out to you about coming on the show again. Usually I'm very allergic to cryptocurrency stuff. However, when it comes to wallets and hack hardware, hacking of wallets, I'm like, okay, I can handle this. And so you have been, you have been recovering coins for people lost in the nether regions of their, of their crypto wallets.

Joe Grand: Yeah. So, so basically this, this all started with I got an email out of the blue, which is typically for me, how things start. A guy was like, Hey, I have a, I have a Trezor hardware wallet. I forgot the pin. I can't access my funds. Can you help? And it was well written enough. That it seemed legit. Cause I get a lot of emails that are clearly like people are bonkers. Scam attempts. Oh, like that. Scam attempt. Just not, not fully there. Um, this one was, was, was good enough where I was like, okay, like I'll, I'll,

Speaker ?: I'll,

Joe Grand: uh, I'll engage. And, uh, wrote, wrote him back and, you know, met, met on the phone, did a little zoom call, saw he was legit. Turns out this guy, Dan Reich is his name is also an engineer and an entrepreneur. So it wasn't like it was a person that didn't know what they were doing or what they got into, uh, which made it really nice. When I started actually hacking on his wallet, I was typing these massive kind of diary entries to him. And like, here's what I did today. And here's what didn't work. And he was actually reading those and being like, well, what if you tried this and this, it was, it was really awesome. So, yeah, so he had a, he had a treasure Harbor wallet and there'd actually already by this point, there had been a lot of research into, and results into defeating security of the readout protection on STM 32s. In this case, the STM 32 F2 and some other attacks against the, the treasure one, various firmware versions. You know, Colin O'Flynn had his attack on, on version 1.7.3, which was a USB kind of overflow issue that he could trigger using electromagnetic fault injection. Uh, the wallet dot fail guys, uh, you know, Dimitri and Thomas Roth and Josh Daco proved that they could do it on, on a treasure wallet on, on a up to version. It got fixed in 1.8, but basically doing fault injection to re-enable the, the debug interface on the board going from RDP two, which is, you know, read protection to the maximum down to RDP one, which gives you debug access, but only to Ram. And then they were able to get into like a firmware update mode that at one point during that process, the private information is, is moved into Ram to protect it while you do a firmware update. And they were able to then grab the contents. So there'd been all of this work. I'm like, yeah, sure. I should be able to take on this, this project and learn a lot more about fault injection, both voltage based, uh, electromagnetic based. Cause I had known about it for a long time. I'd talked at a very high level about it, but never really gotten deep into it. So again, it was one of these things, just like every other project, a great opportunity to try something new and learn something new. And I was like, I can, you know, try to replicate some of the work that's out there and it should be easy. Uh, of course, you know, famous last words, nothing, nothing is as easy as you ever think it is. Right. So it turned into this, you know, three month long effort of learning about all the different fault injection and really building up my knowledge from, from ground level. I was using a chip whisperer. So, so following Colin and new AE technology tutorials of using the chip whisperer and, you know, starting as a noob really. And cause that's for me, like doing it is the way to do it. And I have no problem of saying like, I know that I'm not good at everything. And I know that I'll never be good at, at everything. And I have no problem of like saying, I don't know this, I'm going to go learn it. And it, it was, it, it just happened that Dan, you know, the customer, if you will, uh, was totally open to that. And he's like, yeah, you know, Joe's being transparent and he's sharing his, his failures and successes. And like, so he, he really, he basically was like, if you can prove that you can hack this device two or three times, I can't remember. Then I'll, you know, fly out there the next day and we'll do it.

Chris Gammell: Wow. Can you, can you explain what the, what the chip whisperer and the side channel attack is? I'll link in Collins past episodes in, but, uh, what, what, what is the, what is the thing that you had to learn there?

Joe Grand: Sure. Okay. So, so what I had to learn is an attack called fault injection attack, also known as glitching. This is something where you're basically operating a chip or a device outside of its defined parameters. So if you imagine you look, you look at a data sheet, right? And it's like, this chip is guaranteed to function up to 20 megahertz and down to 1.2 volts. So from a hacker perspective, it's like, all right, what happens if you, you know, quickly operate faster than that, or you brown out the voltage really fast for the core? Like, is that going to possibly a lot of times, usually it just causes a reset or whatever, but sometimes if you hit it just right, it can skip over an instruction or return a different value from a function call. And if you time that with say a security check, in this case on the STM 32, where it's running its boot ROM, when it powers up and it says, do, do I have security enabled or not? If you can glitch at just that right time, it's going to change that. Yes. To a no. And then you have access. So the chip whisperer is really a high end tool to let you do fault injection along with a whole bunch of other stuff. I'm sure Colin explained it, but you know, it can also do side channel power analysis. So basically measuring the power consumption of a device, most importantly, while it's doing like a cryptographic operation and you can pull out the crypto keys. And he's just been, I mean, he's just such a great guy and has been so instrumental in making these attacks that really have been advanced complex attacks into something that anybody can do. Literally anybody can do it. You can buy the tools, run the tutorials and do it. So I reached out to him when I started this project. I'm like, Hey, I saw, you know, some of your work and we'd been friends anyway. I've done a bunch of training classes together and stuff. I was like, you know, do you have any tips? And he's like, yeah, let me send you a bunch of hardware. And then you go through the tutorials. And he basically was kind of my mentor of learning all of the details. And there's so many different parameters and things that can go wrong and the quality of your glitch and the timing and the width of it and all of these things. And he helped me through it. But that's, you know, that's, again, that's a higher end tool. Thomas Roth has a tool that's based on a Raspberry Pi Pico. So you can do it super cheap, really to do the most basic voltage glitching. All you need is a MOSFET and you, you know, crowbar it to ground really fast at the right time and cause something to happen. So that was kind of the process of doing it. And yeah,

Chris Gammell: one of the things that Colin talked about when he was on the show is like, you know, like the whisperer as well. It was like the, it was replaced at least for the side channel stuff. It was like replacing, it was basically replicating and replacing, needing like a scope and like a Python scripting console outside of it. And like all the things that he glued together, he then just like package that up into a circuit board that does a similar kind of thing.

Joe Grand: That's right. Because, you know, there'd been papers about academic papers about side channel attacks, at least since 1999, when some guys at cryptography research had kind of pioneered that Paul Kautcher and those guys. But voltage glitching has been around way longer, at least since the early eighties. It was used a lot for, for pay TV, you know, smart card hacking in the mid eighties as well. But there were never any really accessible tools to help you. And that's the same thing with the J tagulator. And why I made that is at some point, the number of people that can do these things get smaller and smaller until you make it accessible. And then it opens up for everybody. So, I mean, it was just, it was great.

Chris Gammell: So on that, on that point, actually. So is it a good thing that there's, these tools are more available? Like, I think some people would look at that and say like, well, the tools are more available. There's more like, it's more likely that people are going to quote unquote, do hacking, you know, that's said tongue in cheek, of course, but.

Joe Grand: Oh, I mean, that's, you know, that's a great thing. I mean, my, my whole thing is like, yeah, should we, should we outlaw hammers? Because you can use a hammer for,

Chris Gammell: you know, now that you say that. Yeah. Well, you can use a hammer,

Joe Grand: you know, do something good and build a house, or you can use a hammer to smash somebody over the head.

Chris Gammell: Yeah.

Joe Grand: These are tools that educate people about design. They not only let you use it in an offensive way of hacking something, but also in a defensive way to understand your, your risks and your threat to be able to make more secure products. Yeah. And the thing is, if these tools didn't exist, somebody else would end up making the tool and using it.

Chris Gammell: Or there's someone, there's someone that knows how to do it without a tool. So they would just be, and then you just wouldn't think about it.

Joe Grand: Or somebody is going to do it and not publicize it. That's going to put all of us at risk. So yeah, it's a tool. And, you know, we could get into the whole book burning thing right now too, but that's the same thing. You know, books are information. Nobody said book burning, Joe. I don't know where you, I just thought of that, but you know, book, you know, it's information, right? These are information tools. So yeah, I think it's, there's always going to be a conversation about it, but I think, you know, as far as getting them out there to, to inspire people and help engineers and help, help developers make better products and help people like me, who are hackers help other people by, by doing this stuff. What we didn't mention is the wallet had $2 million on it.

Speaker ?: Oh yeah.

Joe Grand: Oh yeah. Small detail. It was a, it was, so it was a little bit of a pressure where I wanted to make sure that the attack was going to work as, as reliably as possible. Right. Cause I didn't want to be the one of like, Oh, you know, he comes all the way here and it's like, Oh, sorry, man. I glitched it wrong. And now you have,

Chris Gammell: he's never going to remember that pin number. It effectively doesn't exist. You know, that's what he's not like.

Joe Grand: Basically. He's basically saying like, I've, I've gotten to the fact that like this money, I might never see it again, but it's still, he, he, he wanted it. Right. So there's an article about it in the verge. That's up right now. Kim's editor. It's super awesome. Journalist wrote a whole story about it. And then we made the video at the same time. So going back to the pizza compass, the chase, the cameraman who lives here, I called him up and I was like, Hey, I'm hacking on this hardware wallet. And actually I wasn't even thinking about filming it, but my wife came in and she's like, Joe, you have to show people what the hacking process is. You know, you're always filming engineering stuff, but that's not where you came from. You came from hacking. Why don't you film it? I'm like, Oh yeah. Okay, sure. So why weren't you wearing a hoodie? That's what I was wondering the whole time. Right. This guy's a hacker. Where's his hoodie? What's funny is a friend of mine who is a filmmaker and entrepreneur, and he was a customer of mine when I was designing that portable monitor years earlier. I was talking to him about it. He's like, yeah, we should totally film this and I'll help you, you know, direct it and edit it and stuff. So I, I got to just do the engineering and explanations without having to worry about it. I was like, I'm going to worry about setting up the cameras and the audio and all of this stuff. And it was awesome because, you know, both of them are so good at what they do. And that I could focus on this stuff. And it, it ended up for a really fun day and really neat adventure and a great learning experience. And I actually have another glitching set up right now. I've done a couple other fault injection things since then. I pulled some firmware out of an NRF 52 of a medical device just for fun. But I have another setup right now that I'm doing also STM 32 related. And yeah, since the video came out a couple of days ago, we've gotten tons of emails of people asking for help with software wallets, hardware wallets, a lot, there's a lot of cryptocurrency scams as well. So people are like, you know, I, I dropped all my money and I can't get it back, which of course we're not able to help with, but I, cause I've never, I would never really paid attention to cryptocurrency either until, you know, Dan emailed me.

Chris Gammell: Until it might, might pay an invoice. What's that? I said until it might pay an invoice. And then it's like, Oh yeah, yeah, yeah, yeah. No,

Joe Grand: this is a converted. It's a USD to fiat. This, this,

Chris Gammell: this could become future peaches that I, that I navigate to.

Joe Grand: That's right. But yeah, I figure like, you know, even if people don't like cryptocurrency, my perspective is if somebody can't get access to, their legitimately owned money, like why not use my skills?

Chris Gammell: I kind of put you in the locksmith category at this point. You know, you're a digital lock. I mean,

Joe Grand: I'm an equal opportunity hacker and you know, I'm not going to judge what, what type of currency they have, but if I can change somebody's life or help make somebody's life better, isn't that kind of the point, whether it's, you know, releasing a tool to help somebody giving a talk to inspire somebody to share information or like use some skills that are cool. And that was kind of the realization too, and I think that comes back to like my burnout period of like, what am I going to do? And of course it's, you know, hacking is really hard. Like this took three months and that was with known information. There's a lot of wallets that haven't been hacked though. You could argue everything is hackable. It's just, you know, is it worth the amount of time and money and effort that you want to put into it? So, you know, I'm not going to, it's not like I'm going to be hacking every single wallet all the time, but another thing also going back to admitting that I don't know everything and I never will. I see no problem with reaching out to people that do have the skills that we need. Right. And, and do some like, Hey, I, you know, we have this guy that came to us and he needs help with this. And Colin, you're the master of fault injection or, you know, all these friends in that industry, in our community that, that have these skills that we can all work together to help somebody. Like, I think that's kind of cool. And maybe it's not just cryptocurrency. Maybe it ends up being, you know, somebody dies and they have a, they have some password, you know, on their, on their bios that we need to crack open the machine and like get the, read the contents off the double E prom or whatever it is. Like there's all these, all these opportunities of using, using skills for good and not making it a competition, but really kind of making it a community and helping people. And like, of course the money's getting money is nice, but it ultimately doesn't end up being that much if you're taking a, you know, a small percentage of things in exchange for, for doing the work and not getting paid for, you know, doing the work in advance and things like that. But money's not everything, right? Sure. I think. So yeah,

Chris Gammell: you'll find out. So on the, on the, the actual hack itself, I mean, so on the, the, I watched the video. I think, I think everyone listening to this should definitely go watch the video, but was it that, that, that glitched, that you were talking about when it was moving stuff over? What, what was the actual, like digging through the Ram and like, what, what was the mechanism that ended up being allowed you to extract the required pin number?

Joe Grand: Yes. Okay. So for this particular one, so I'd mentioned there had been some previous, you know, known attacks against the treasure. I had started out just trying to replicate the wallet dot fail attack, which was you, you glitch the device and then you basically have the firmware of the treasure go into this firmware update mode and it moves, it moves the contents there. When I was trying to do that, the, the device was like kind of getting into this frozen mode where I could still connect to the debug interface after glitching it, but I couldn't manipulate the buttons to get it into the firmware update mode. So I was just kind of messing around with things. And then one, one day accidentally somehow I was able to read the Ram and the contents were there. So then I went down this whole, this whole exploration of like why that happened. It turns out for this particular version of firmware of this device, the private information. So the recovery seed, which is essentially correlated to your, to your private key and the pin that gives you access to your device. Uh, so the critical contents were copied into Ram on power up. I don't know what the reasoning was for that. Like maybe it's faster to access that out of Ram. And you know, they're, they're relying on the security of the chip and the security of the chip is supposed to not give you access to Ram. So from a design perspective, they're using the, the, the security as it was intended.

Chris Gammell: Yeah. The vendor supplied. Yeah. Solution probably.

Joe Grand: Yeah. But it just happened that I don't know why they did that probably for speed or for, you know, some sort of efficiency reasons. So when I looked through the source code, cause this was an open source product, so it made it easier. If it was closed source, you could still hack it. You would just have to take more time to get through everything to reverse engineer more stuff, but the code was open source. And I found the line of code that was doing the mem copy of that information. So I knew it was getting into Ram. And then I just had to figure out the right timings to defeat the security of the STM 32 and make sure that the contents were, that I was glitching basically before anything has happened happening, but not too late in the process where it might glitch, but the contents aren't there. So it was very timing finicky, but yeah. So basically you glitch the, the STM 32 that's going to downgrade to RDP level one. Give you access to Ram and then using a Sega J link with SWD, which every time I would glitch, I was basically querying, like, do I have access? Do I have access? Do I have access? Can I read anything? It gave me access. And then I could just do a, you know, dump dump Ram area and then run strings on it. And that's going to actually just show you the, the, the printable text, you know, ASCII readable text of the, of the contents of memory. And they, and there they were in the clear.

Chris Gammell: Hmm. So let me flip this on you. Cause I mean, you've designed products in the past as well. So like if you were going to design a very secure product, maybe, maybe not a wallet, but, but what would be some of the things that you would put into place so that some of this stuff wouldn't be possible? Obviously they've, they've read the code. I saw on the video, they've read the code. It's since, since the 1.6 or whatever, and that's no longer possible. But if you think about like secure design, cause I think a lot of people listening are like, okay, well how do I make sure Joe doesn't get access to my device? Yeah. What are some things that you think about there?

Joe Grand: Yeah. I mean, it secure design is so hard and it's exactly, it's so hard that I don't normally like give talks about it. Right. Because it's that hard. It's very product specific and it really comes down to, I guess what you would call like threat modeling is kind of the term of when you're designing your system, thinking about what an attacker wants to do. Like what would their goal be of the system? So in the case of a hardware wallet, the primary goal is to get access to that private key. So you would need to take, you know, steps to design that. I would end up trying to find in that case, say like a secure microcontroller from a vendor that at least has some additional security features, not just code protection, but some memory segmentation, some better access control within the silicon itself. You know, like arm trust zone or something like that. And of course there have been vulnerabilities and problems with that stuff also, but at least you're implementing more, more security features.

Chris Gammell: So basically stack up as much hardware security as you can by buying your way into, into that realm to start with.

Joe Grand: The problem though, is that a lot of these secure microcontrollers and security based devices are, they're not that easy to work with. And I feel like until the silicon vendors make it easier for engineers who are not security people or don't understand cryptography or aren't hackers implement this stuff easily, it's, it's, they're not going to be as adopted as well. Another problem that in the article it's mentioned, one of the founders of, of the treasure device had commented, like they, they were looking into using a secure element in their, in their product, which other hardware wallet vendors do, but they are closed source. Treasure wanted to keep everything open source. And the vendor wanted them to sign a non-disclosure agreement. And they're like, well, that's, that's not good for us because, you know, then our customers don't know about the chip, but furthermore, if they do their own analysis on it and find a security problem with it, now they're bound by this confidentiality agreement and can't tell people about it. And then what do you do if you have a secure device in a, in a product and you can't tell your customers that it's insecure, that, you know, you're, you're kind of in a pickle at that point. Yeah. I mean, maybe even a legal pickle.

Chris Gammell: Yeah. I mean, there's,

Joe Grand: there's a legal pickle. Right. So I feel like the chip vendors need to maybe open up a little bit and not make it so difficult to start designing with those parts and making it easier for, for engineers to build those things in. But it, it, again, it might not, that might not be the right solution for what you're doing. It might be, you need better physical access or you need, or, you know, better physical access control. You might need better network design. If it's an internet of things device, like it really comes down to like, as you're designing your product, make a list. If I was a hacker, what would I need to go after?

Chris Gammell: Yeah. I've been, I've been catching a lot of, uh, Datco, Josh Datco puts a lot of stuff on LinkedIn about, and he keeps referencing this one list of like security vulnerabilities, like top 10 security vulnerabilities or something like that.

Joe Grand: It was like an, an OWASP, OWASP list. Yeah. OWASP.

Chris Gammell: That's it. Yep. Yep. Yep. Yep. I remember what it stands for, but, and it's like not being able to update your firmware or having easy physical access, like leaving your JTAG port just open and like, you know, after programming. So it's super easy to get to like, that kind of stuff is like bad.

Joe Grand: Yeah. I mean, using, using a list, you know, there's common criteria certification. There's FIPS 140 certification, the OWASP list on my website. If you go to the security section of my website, there's a presentation called something about, uh, every cloud has a silver lining or something, which talks about security problems hacking, but then it has like a list of resources. I'm pretty sure it's still up there. If it's not, I'll put it back up. And at least it's a starting point where you can go and get lists of like what you, what you should try to do and what you shouldn't do. But implementation is always the problem. And that's the hardest thing is like, it's so easy to say, well, you should, you should, all of your content should be encrypted, you know? So, so somebody can't get to them, but it's like doing that in a way that is manufacturable and testable and serviceable, you know, engineers don't think like hackers and hackers. A lot of times don't think like engineers. Yeah. So it's definitely a hard problem, but really, yeah. Start with that threat modeling, look at some resources that are out there and do your best. And then maybe, you know, ask for help and maybe pay someone, pay someone for some advice, pay someone for some advice. Yeah. You know, there are a lot of guys in the industry that will do that. I don't, I don't really do that as much, but there are resources out there and it's hard and you'll never be a hundred percent secure. You just want to do your best and hope that, you know, you're not the one that that's targeted.

Chris Gammell: Yeah. Yeah. I, you know, I think back on like some of my stuff that I've designed in the past and nothing has been super critical, you know, like thinking about like what people would actually go towards. I've done some industrial equipment, but like on networks that were not physically accessible outside of the facility and stuff like that. And even then I was not working on the parts that really mattered. And so, but like, but just like thinking through all these things, like if you're close to money, yeah. Anything in like a money kind of context where you're just like worried that someone might, if you, if you're worried someone's looking over your shoulder while you're, you're you know, designing this thing, then yeah, you probably should be thinking about the security piece for when it's out of your hands. Right.

Joe Grand: Yeah, you have, right. It also depends as your product designed for end users where they have physical access or somebody else can get physical access, or is it inside a facility that maybe the only physical access is going to be an insider threat. And that just all has to be, has to come into, into your design. And you, you want to build that stuff in early, you know, like the internet was never designed to be secure. It was designed to be this open communication channel. And now we're trying to build this entire, our whole world is based on it. And we see internet problems all the time because you're kind of patching security on top of it. And that doesn't work. So you really want to try to try to get your thoughts on security and build it in at an early stage and then get some hackers to hack on it. Also, like if you have, you know, people within an organization that are curious about, about doing this, it's like use some of these tools that we've talked about and see how they affect your product and then see how you can fix those.

Chris Gammell: That's good advice. That's good advice. Joe, when our conference is coming back, can you answer that for me, please? Because I would like to hang out with you in person. It seems,

Joe Grand: it seems like soon I'm getting actually a lot of, a lot of emails about conferences. Okay. I feel like this year and you know, it's, it's still going to be, we'll have masks and we'll maybe hang out outdoors and whatever, but I feel like we're going to start to get back together soon. Like even last year at the, at the end of last year, at the end of 2021, I'd traveled, you know, all over the world to, to kind of catch up on all of the hardware hacking training that I do. And, you know, granted those weren't conferences, but the fact that companies were starting to open up and let their employees go in was good. So yeah, hopefully, hopefully soon. So we can hang out and, and see, see everybody again and not just stare at screens all day. We'll be awesome.

Chris Gammell: I don't know if we're going to fix that one anytime soon, but you know, maybe not all day, but yeah, that's right. Step away for a little bit to show off what we're working on. We've kind of picked this path for ourselves. Yeah, that's right. Yeah. There's a lot of, there are a lot of screens involved. What, what are you excited about building next? If anything, wait, I should, I should step that back because you said people are always asking about what are you doing next? Yeah. What are you excited about Joe? It doesn't have to be electronics.

Joe Grand: Yeah. So, well, so there's a couple of things I'm excited about from the electronic side. One of them is to hopefully again, NF conferences come back, give a talk about some of the actual technical details of some of these things. So not the high level video and stuff, but you know, the real setup and the reverse engineering that had to happen with getting my fault injection stuff, working with the wallet and with this medical device and other things. So just to, I just want to kind of have this presentation that I can share. So I'm excited about that because that's eventually going to happen. And there is a, another kind of pizza compass esque video, not for wired, but for another company that saw the pizza compass and was like, Hey, like, can you do something for us? I'm really excited about that. Cause it's another one of these things where I have free reign and it's going to be like, you know, a wild artistic circuit board with some really cool. Different technologies that this company makes that I have never used before. So, you know, it comes back again to like messing around with stuff that I've never done. So I have some ideas for how to, how to, how to make that. I have no idea when that's going to come out, if that will come out, but if it does, hopefully this year or something. And I'm just excited about it. Cause I already, it's like, I want to try all these different concepts of making this board and stuff. So we'll see. And yeah, I guess I don't really know. I just, I'm just excited to, you know, be able to wake up and be healthy and hack on stuff and take care of my kids and see my kids every day, which before COVID wasn't happening. And, you know, we're all kind of still struggling through just to make sure that everything's okay. And, but it's, yeah, I'm just, I'm just happy.

Chris Gammell: Great. That's great, Joe. I'm, I hope that continues for a very long time. I do too. Yeah.

Joe Grand: So, yeah. And thank, you know, thanks again for, for talking. It's, I still can't believe it's been 10 years, but it's awesome to come.

Chris Gammell: It's been like nine and a half,

Joe Grand: but okay. Okay. That's, that's still a lot, you know, like it's, yeah, that's, I mean, that's a fourth grader. My youngest son, I think my youngest at, at that time, my only, my only child was like three. And now he's, you know, a full on teenager. Yep. Minecraft playing teenager. And it's like, wow.

Chris Gammell: Yeah. Yeah. They, and then our,

Joe Grand: then our second one is, is also up there. So yeah. You know, thank, thanks for, for having me. And, and if people are actually listening, thanks for listening and feel free to contact me. You know, it's like, if I'm happy to answer questions about things too.

Chris Gammell: How are you back on the Twitters? Can people find you there? Yeah,

Joe Grand: I'm kind of on, I'm kind of on Twitter. Like I'll post stuff on Twitter, but I don't really respond very much. Got it. Got it. Okay. The best way is if you go to my website, grandideastudio.com, go to the contact page, fill out that. And then I will, I'll answer that way. Cause email is just a little easier for me. Cause I can actually think about what I'm going to write. It's one-on-one. It's not this massive, you know, everybody doesn't see what I'm saying all the time. Cause I'm, you know, I am a hacker and I am still paranoid, mostly not what people see, but what all these, you know, companies are harvesting my data and stuff. And then as far as wallet hacking, I have a, you know, a temporary, pretty bad website off spec.io that has a contact form for, you know, if you have cryptocurrency wallet problems, but you know, either way getting in touch with me, email works best.

Chris Gammell: And I think you should make like a ghostbusters esque style commercial, you know, like, are you having problems with your crypto wallet?

Joe Grand: Call us today. We've thought about that. I mean, you know, cheesy videos are what I'm all about. So maybe one of these days that will happen.

Chris Gammell: Good. Good. All right, Joe, thanks for coming on. We appreciate hearing from you again.

Joe Grand: All right. Yeah. Thanks again.

Topics

CryptocurrencyDEF CONHackingHardware SecurityJTAGRP2040SecuritySTM32TrainingTrezorWallet

Keep current

Every episode, plus the occasional job post, in your inbox.