Entry Sign Takes Two Ponies for AMD’s Seven-Year NIST Key Mistake

▶ Watch (2:58)

AMD used the example key from the NIST specification for over seven years. That’s what Entry Sign exposed, and it earned two Pwnie Awards at DEF CON 33: Best Desktop Bug and Best Cryptographic Attack. The research, by Matteo Rizzo, Christopher Jenke, Josh Eids, Tavis Ormande, and Eduardo Velanava, showed the key was baked into production CPUs. Winners accepted with a thank-you to AMD for “a kind of epic fail” and an apology to everyone who had to patch their CPUs.

Tunneling Hosts and Side Channels Win the Research Awards

▶ Watch (10:07)

Most Innovative Research went to Angelos Beias for “Haunted by Legacy,” discovering and exploiting vulnerable tunneling hosts. Nobody from the team was present to accept. Most Underhyped Research went to “Scheduled Disclosure” by In Wen Chan, Isabella Su, and Ricardo Pockinella, proving remote power side channel attacks work on modern x86 CPUs without frequency side channel leakage. That result challenges assumptions about the threat model for CPUs without the usual leakage vectors.

Multi-Bug Chains and Race Conditions Win Mobile Bug and Privilege Escalation

▶ Watch (16:11)

Best Mobile Bug went to Ken Ganon of NCC Group for exploiting the Samsung Galaxy S24 at Pwn2Own, a multi-bug chain demonstrated on stage. A ZDI colleague accepted on Ganon’s behalf. Best Privilege Escalation went to the Linux kernel vis quadruple race condition, where orchestrating a race among four threads triggers a use-after-free. Discovered during a CTF, the bug was accepted by a researcher whose co-worker Hanuk Kim could not attend.

OpenSSH Pre-Auth RCE Wins Best RCE; Linux CNA Repeats as Lamest Vendor

▶ Watch (22:00)

Best RCE went to Regression, Qualys’s OpenSSH signal handler race condition, the first pre-authentication RCE in the default OpenSSH configuration in nearly 20 years. Lamest Vendor Response went to Linux’s CVE CNA, second year running, for dismissing a critical out-of-bounds write in HFS+. A crowd member accepted the award and questioned whether Linux even counts as a vendor, since nobody paid for it.

Signalgate Takes Epic Fail; Two OpenSSH Bugs Win Epic Achievement

▶ Watch (30:54)

Most Epic Fail went to Mike Waltz for Signalgate, after he added a journalist to a Signal group chat containing classified military discussions. The Summercon Foundation presented a t-shirt reading “signal groups kill troops.” Epic Achievement went to Qualys for finding two OpenSSH vulnerabilities. A Qualys employee who did no research accepted the award, joking he was taking credit for his colleagues’ work.

Notable Quotes

You don’t get an extra pony. Sorry. Ian Roos · ▶ 7:54

Well, this is awkward, but thank you. Entry Sign team · ▶ 8:07

Better luck next year, gang. Ian Roos · ▶ 9:11

reminder that signal groups kill troops. Mark Trumpbour · ▶ 32:19

Key Takeaways

  • Entry Sign won Best Desktop Bug and Best Crypto Attack for exposing AMD’s seven-year NIST example key reuse.
  • Qualys’s Regression, the first pre-auth RCE in OpenSSH’s default config in nearly 20 years, won Best RCE and Epic Achievement.
  • Mike Waltz won Most Epic Fail for adding a journalist to a Signal group chat containing classified military plans.