Michael Mouchous
@mickm111
Followers
39
Following
109
Media
0
Statuses
83
Paris, France
Joined July 2009
What if a hacker could gain total control of your smartphone, not via malware, but the hardware itself? The @DonjonLedger discovered a potentially unpatchable flaw impacting MediaTek Dimensity 7300 - a popular Android phone SoC - enabling arbitrary code execution in minutes.
14
38
182
The absolute highlight? An exclusive tour of the *Ledger Donjon* 🛡️. This is Ledger's top-secret lab where their white-hat hackers relentlessly attack their own hardware (and competitors') using side-channel attacks, fault injection, and more. Their goal: Find vulnerabilities
1
2
4
Struggling to explore waveforms with millions of points? Discover TurboPlot ⚡ 👉 https://t.co/8qtvylIaCY
3
8
20
🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer. As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app. 👇🧵
174
94
415
Security leaves no room for error, a single variable mishandled, and the entire security model can collapse. We're excited to share an illustration of this through our recent research on the Tangem card. Big thanks to the @Tangem team for their responsiveness and collaboration!
🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer. As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app. 👇🧵
3
5
23
DevOps practices are all well and good, but beware of the configuration of the tools that access your production. Find out more about Argo CD misconfiguration in this new blog post. ⏬ https://t.co/56FTTAuR3C
#argocd #security #devops #devsecops
ledger.com
Despite such a strong security posture, Argo CD can be configured in ways creating vulnerabilities. This article studies on two examples where Argo CD is deployed in a way which unexpectedly enabled...
0
6
14
Last week at @hardwear_io NL 2024, we showcased some of our attack tools we use in the Donjon, and a live demo of a double fault injection ⚡️⚡️ with the transportable laser bench! Our tools are open-source and presented on our webpage: https://t.co/ulu1YsAxZu
2
1
11
🔬 Live Fault Injection Demonstration! Join @mickm111 at #hw_ioNL2024 as he showcases lightweight test bench utilizing laser injection and simple optical hardware. See fault injection methodology in action 🤓⚙️ 👉 https://t.co/aHPpdlCpST
#faultinjection #hardware #donjon
0
2
5
This week the Donjon brought its transportable laser bench to the https://t.co/xrCRQEAv2a conference in Rennes by train 🚄. A proof that a functional Laser Fault Injection bench is not that impossible to see anywhere. Next step in the Village @hardwear_io NL 2024 conference!
0
9
35
During next @hardware_io conference, @DonjonLedger will showcase tools developed and used for Fault Injection Attacks! Pass by in the Village to see a part of our Tool Suite: Scaffold, Silicon Toaster, Laser Studio, QuickLog, Curmea… operating on our transportable laser bench!
Unlock new levels of precision with hardware tools such as Scaffold, Silicon Toaster, and Curmea! 🛠️✨ Ideal for precise perturbations in operations including current regulations, signal generation, process disruption Join @mickm111 at #hw_ioNL2024 👉 https://t.co/aHPpdlCpST
0
1
6
Ledger will be in Nashville for @TheBitcoinConf this week! We’re eager to spend a week fully immersed in the Bitcoin world, with leading speakers, educators, and inspiring keynotes. Stay tuned for an exciting announcement of our own! Scroll down to learn more about how you can
14
32
116
Exciting news from @DonjonLedger! Introducing cargo-checkct, our cutting-edge tool to protect against timing attacks. Curious about what timing attacks are & why typical solutions don’t quite cut it in crypto? Dive into our latest article to learn more!
ledger.com
The Ledger Donjon team is thrilled to present cargo-checkct, our in-house tool designed to defend against timing attacks. In this article, we'll delve into the concept of timing attacks, explore why...
29
14
52
We are thrilled to have open-sourced cargo-checkct, to help bridge the gap between academic research and industry practices for the early detection of timing vulnerabilities in cryptography libraries. Read more about it in our blog post.
ledger.com
The Ledger Donjon team is thrilled to present cargo-checkct, our in-house tool designed to defend against timing attacks. In this article, we'll delve into the concept of timing attacks, explore why...
Exciting news from @DonjonLedger! Introducing cargo-checkct, our cutting-edge tool to protect against timing attacks. Curious about what timing attacks are & why typical solutions don’t quite cut it in crypto? Dive into our latest article to learn more!
0
5
9
Don't let the bull run away with your beer, catch it with NanOpener - the bulles market's best friend! https://t.co/YkIWHPm7dT
34
9
144
The wait is officially OVER. Our brand new #ledgerplex in @thesandboxgame is live! Let the learning commence!
22
52
196
Ever wondered about the basics of side-channel attacks? In the late @MISCRedac edition (in French), you can learn the underlying principles of such threats, and discover how to use our 🌈 Rainbow tool to assess the security of your code!
github.com
Makes Unicorn traces. Generic Side-Channel and Fault Injection simulator - Ledger-Donjon/rainbow
Les attaques par canaux auxiliaires sont décortiquées dans notre nouveau numéro, en kiosque dès aujourd'hui & disponible également sur https://t.co/xbXlwCjoE9
#sidechannelattack #crypto
0
4
16
Olivier will be present in https://t.co/QsHhtdEuyU next week to present his huge work on the ATECC608B: a Triple Exploit Chain done with our laser benches in the @DonjonLedger! #hw_ioNL2023 #hardwaresecurity #Conference
⚡Laser #FaultInjection on a Secure Element! 🔎Olivier Heriveaux discovered a new vulnerability in the newly released Microchip ATECC608B, allowing an attacker to extract internal EEPROM masking keys Know more➡️ https://t.co/Xo0HEmYPF3
#hw_ioNL2023 #hardwaresecurity #Conference
0
10
20
The video of the presentation on the hardware vulnerability identification (T-test) and exploitation (double laser fault injection) is finally out! You can view it there: https://t.co/mHwhM2YSTA
Donjon is going Deeper! This weekend at FDTC2023 in Prague, Karim Abdellatif (@k15ab_ ) and Olivier Hériveaux presented their findings on DeepCover DS28C36 thanks to the usage of T-test and Double Laser Fault Injection. Check out their presentation slides: https://t.co/IfjEKlbnCD
0
6
19
"Security is not static, it is a journey - you always try to break your own product, and that forms the foundation of what you are going to work on next." -@p3b7_ Check out @danheld's security journey to the @donjonledger with our CTO @p3b7_.
14
24
71
Podcast 🎙️ The Laws of Stan - Understanding the Mathematics behind Blockchain https://t.co/Y4CHWYnzMk
1
2
14