Device Security Bulletin | Issue 71
Keysight Device Security Testing
Riscure Security Solutions, a Keysight Technologies device security research lab
Security Highlight: Back in the Driver's Seat
This security highlight details?the recent Tesla Autopilot hack, presented at the CCC conference by researchers at Technische Universit?t Berlin . Interestingly, Fault Injection was utilized to compromise a vehicle's autopilot system. Their findings shed light on potential security risks in modern automotive systems.?
Click below to read more about the details of their approach.?
News and Updates
Riscure Workshop 2024: Join us this spring in Austin, Texas!
We're thrilled to announce the return of the Riscure User Workshop to the vibrant technology hub of Austin, Texas! This is our annual event that serves as a platform for sharing the latest developments both at Riscure and in the broader field of device security. We’re switching things up this year, our workshop will span over 2 days and will take place on April 30 & May 1, 2024.?
The first day (April 30) will be free for everyone to attend & participate in the intriguing presentations & hardware demos; the second day (May 1) will be a full-day training from one of our very own talented Security Engineers. The training will cover SCA & FI at an expert-level, with hands-on training with our Hardware tools. The price for the full-day training is $450. If you register for both days, you will receive a 10% discount off the training. Moreover, when you sign up for the training, you will be given a 15% discount code which a colleague can redeem if they would like to join the training as well.?
We hope to not only connect with existing and prospective customers of our Inspector product range, but we also want to offer attendees practical knowledge that they can apply to their daily tasks and research endeavors. Throughout the workshop, we'll share insights into the latest advancements in Pre- and Post-Silicon SCA & FI security, demonstrate the capabilities of our hardware tools, and discuss recent research endeavors. Attendees will also have the opportunities to network and collaborate with peers from various companies and industries, specializing in embedded hardware and software solutions.?
If you’re interested in participating & attending this year’s 2-day workshop,?register by filling in the form at the bottom of the webpage.
Riscure Side Channel: Join us for a special webinar on March 28.?
We are introducing the brand-new webinar series – Riscure Side Channel – created to connect our customers with Riscure’s experts on key topics in the industry.?Every two months we will discuss the latest events in device security. This includes notable attacks, research and product updates, both within Riscure and externally. We choose the topics that are important for our customers and also invite you to ask your own questions. The first installment of the ‘Riscure Side Channel’ series will take place on March 28, 2024 at 4PM CET/10AM EST. Feel free to register via the link below.?
Inspector Software Update: No more dongle needed!?? ?
As of the last release, Riscure Inspector software does not need a physical dongle anymore to check the validity of your license. Inspector can run without a dongle which will have benefits for you when you want to use Inspector remotely, on a server or when you would like to install and use Inspector on multiple workstations. The license server can be activated on or offline, based on your preference and will work both for Windows and Linux.?
To work with Inspector without the need to use a dongle, you will need to install a local license server. This license server can be installed on the machine which has Inspector installed or in a (offline) network environment. How to install and configure this license server is described in Inspector documentation and our customer team will be happy to assist you in case of any issues or questions upfront.?
In 2024 new licenses and or renewals will by default be delivered to work with the license server option. Though for backwards compatibility we currently still have support for a physical dongle, our intent is that this option will not be available anymore as of 2025.?
Webinar: How to secure SoftPOS mobile apps to comply with PCI MPoC?
Join us on February 27th, 10 am EST / 4 pm CET for a webinar in collaboration with Guardsquare! Anton Baranenko , Guardsquare's Product Manager, and Arno Buijten , Riscure's Senior Evaluator, will guide you through the intricate world of SoftPOS security. Learn more about the PCI MPoC standard and what it means for SoftPOS apps.?
My internship at Riscure: Simon Gao?
Meet Simon Gao (Simon Gao), who has recently completed his internship at Riscure! With prior experience as a Security Analyst in China, Simon felt ready to take the next step and seek deeper knowledge, enrolling for a master’s degree in the Netherlands.
Click here to learn more about his intriguing research and take a sneak peek into the Riscure work culture.?
领英推荐
Riscure?Announces Strategic Partnership with EndoSec, LLC.?
Riscure is pleased to announce its strategic partnership with EndoSec LLC . Our goal is to increase the accessibility of Riscure’s industry leading security test tools to the U.S. Government, specifically to agencies such as the United States Department of Defense (DoD) and defense contractors.
Meet Riscure During These Upcoming Events
GOMACTech 2024?
Riscure will exhibit at the?upcoming GOMACTech conference, which will take place on March 18-21 in Charleston, SC. You'll find us at?Booth #214, where we'll be available to discuss our solutions in more detail and explore potential collaborations. If you'd like to schedule a dedicated meeting in advance, please reach to us at?[email protected].?
Digital Forensics Research Conference?
Our team will be visiting the upcoming Digital Forensics Research Conference, held on March 19-22 in Zaragoza, Spain. DFRWS conferences provide a friendly atmosphere to share research papers, practitioner presentations, and works in progress. Every gathering includes technical workshops, demos, panels, and other “breakout sessions” covering various issues related to digital forensics.
?Go to the event website?to read more and register.?
Embedded World Conference 2024?
Meet Riscure experts on April 9-11 in Nuremberg, Germany at the Embedded World Conference, and discover innovations driving the industry forward. Perfect for engineers, developers, and professionals in embedded technologies.
?Go to the event website?to read more and register.?
Insomi'Hack?
The next Insomi'Hack event takes place on April 22 and 26 in Lausanne, Switzerland, and the Riscure team will also attend. Engage with leading experts, participate in hands-on challenges, and explore the latest trends in offensive and defensive security. Perfect for device testers, security professionals, and enthusiasts eager to elevate their skills.?
Go to the event website?to read more and register.?
COSADE 2024?
Our team will be present at the upcoming COSADE conference in Gardanne, France on April 9-10, and delve into the world of hardware-oriented security. Ideal for researchers, academics, and industry professionals interested in the latest advancements in hardware security.
Go to the event website?to read more and register.?
If you would like to connect with our team at any of the above events, please don't hesitate to get in touch with us via?[email protected].?
More About Riscure
Become a part of our team!?
Riscure is always looking for talented professionals to join our dynamic team and to help us further develop our testing and knowledge products!?When joining Riscure, you join one of the leading companies in the industry and a fun and exciting team of professionals to work with.
Find out more about what it is like?working at Riscure on our website.?We have open vacancies in different departments and within various positions. Are you ready to join our team??
Join us on Twitter and LinkedIn?
In addition to monthly newsletters, we regularly share updates on our social networks. If you are not subscribed already, check out our accounts on?Twitter?and?LinkedIn.?