YoVDO

How I Can Unlock Your Smart Door - Security Pitfalls in Cross-Vendor IoT Access Control

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cloud Computing Courses Access Control Courses Formal Verification Courses IoT security Courses

Course Description

Overview

Explore the security vulnerabilities in cross-vendor IoT access control systems through this 35-minute Black Hat conference talk. Delve into the complexities of cloud-mediated device management and the emerging capability of delegating device access across different clouds and users. Examine real-world examples involving popular IoT vendors like Philips Hue and August Lock, and their integration with cloud providers such as Google Home and Amazon Alexa. Learn about the potential risks associated with convoluted delegation chains and authorization operations. Discover the findings from formal verification and vulnerability discovery processes. Gain insights into specific vulnerabilities identified in cross-vendor IoT access control systems and their implications for smart home security.

Syllabus

Introduction
Background
Example
Formal Verification
Vulnerability Discovery
Presentation Overview
First Vulnerability
Second Vulnerability


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube