<<39C3 Power Cycles
  • <<39C3Power Cycles
  • Schedule Calendar
  • Schedule List
  • Speakers
  • Help
  • Legal
  • <<39C3Power Cycles
  • Schedule Calendar
  • Schedule List
  • Speakers
  • Help
  • Legal

EliseZeroTwo

This speaker has not yet provided information about themselves.

Events with this speaker

Day 3
14:45
60m
Making the Magic Leap past NVIDIA's secure bootchain and breaking some Tesla Autopilots along the way

The Tegra X2 is an SoC used in devices such as the Magic Leap One, and Tesla's Autopilot 2 & 2.5 promising a secure bootchain. But how secure really is the secure boot? In this talk I go over how I went from a secured Magic Leap One headset, to exploiting the bootloader over USB, to doing fault injection to dump the BootROM, to finding and exploiting an unpatchable vulnerability in the BootROM's USB recovery mode affecting all Tegra X2s.

SecurityZero