Come see how I used my jerry-rigged “EMBite” probe to capture an EM side-channels using a HackRF.

I used this to figure out the precise timing of where a completely unknown boot check fails - and then used that timing to bypass the check 😁

https://www.offensivecon.org/speakers/2024/stacksmashing.html

Thomas Roth (stacksmashing) | OffensiveCon