OpenSecurityTraining2

386 Followers
5 Following
159 Posts
501(c)(3) Non-Profit providing Open Source and Open Access computer security training material. #OST2 re-launched July 2021!
Websitehttps://ost2.fyi
LinkedInhttps://www.linkedin.com/company/ost2
Reddithttps://reddit.com/r/OST2
Twitterhttps://twitter.com/OpenSecTraining
BlueSkyhttps://bsky.app/profile/opensectraining.bsky.social
Threadshttps://www.threads.net/@opensecuritytraining
Why read about TPM 2.0 in a spec when you can drive it with Python? 🐍 TC2202 teaches real-world TPM programming with tpm2-pytss, taught by its author, Bill Roberts. Hardware-backed crypto, hands-on labs, no fluff. https://ost2.fyi/TC2202
Move from basic fuzzing to a high-performance workflow. Fuzzing 1001 https://ost2.fyi/Fuzz1001 bridges the gap between theory and practical research. Master AFL++, PCGUARD, LTO, and ASAN using real CVEs from Xpdf and tcpdump.
Tired of guessing inputs? Let the computer do the work! Learn about symbolic execution from @barbie in "Reverse Engineering 3201" https://ost2.fyi/RE3201 and use SMT solvers to find the exact inputs to reach vulnerable code. Stop guessing, start solving! 
We're happy to say that we're now over 34k students at OST2! 🙌🥳🚀
We're in discussion to form a partnership with the UEFI Forum. But as part of that we need to propose classes that can be taught on the topics they're involved with. Things like UEFI Measured Boot in particular would make a lot of sense now that we have robust TPM classes at OST2. But any topic is welcomed and encouraged! HMU at that email below if you're interested in getting funded to create a class and make it freely available to the world!
From: @OpenSecurityTraining2
https://infosec.exchange/@OpenSecurityTraining2/116182627920813041
OpenSecurityTraining2 (@[email protected])

OST2 is putting out a request for proposals for an opportunity to be funded to create classes on UEFI and/or ACPI. If you are interested, please reach out to teach🌀ost2.fyi with a proposed class syllabus. https://ost2.fyi/Training-RFPs.html

Infosec Exchange
OST2 is putting out a request for proposals for an opportunity to be funded to create classes on UEFI and/or ACPI. If you are interested, please reach out to teach🌀ost2.fyi with a proposed class syllabus.
https://ost2.fyi/Training-RFPs.html

RE: https://infosec.exchange/@OpenSecurityTraining2/115847996736615238

Final call for beta testers! The class will begin later today!

We are happy to announce that AMI has become a 🥇Gold-level sponsor of #OST2!

Learn about their work creating firmware across the industry here: https://ost2.fyi/Sponsor_AMI_SM

RE: https://infosec.exchange/@OpenSecurityTraining2/115847996736615238

Our Trusted Computing "Advanced TPM usage" class will begin this week. Sign up below.

📢Call for beta testers!📢
https://forms.gle/9QgwVSstXi7nVgVNA

The beta for Trusted Computing 1103: Advanced TPM Usage will start Jan 16th. It will take ~7 hours to complete. If you're interested in participating, please sign up above. (Note: http://ost2.fyi/TC1101 & http://ost2.fyi/TC1102 are strongly recommended prerequisites.)

Like TC1101 & TC1102, TC1103 has the goal of helping developers get bootstrapped on using TPMs more quickly than if they were to just rely on reading the spec or API documents alone.

The topics for TC1103 are:
- Introduction to the Feature API (FAPI)
- Creating keys using FAPI
- Policy using FAPI
- Full-disk encryption primitive (FDE) using a TPM
- TPM operations for FDE
- Advanced TPM Policy usage using tpm2-tools and tpm2-tss
- Policy using locality
- Policy using the TPM clock and reset
- Policy using the TPM's internal NVRAM
- Handling external keys using a TPM

TC1103: Advanced TPM Usage Beta Testing Pre-Class Survey

TC1103 will take approximately 7 hours to complete, and will begin January 16th, and end February 13th. TC1103 is the follow up to TC1101 Intro TPM usage (https://ost2.fyi/TC1101) & TC1102 Intermediate TPM usage (https://ost2.fyi/TC1102). It will cover the following material: - Introduction to the Feature API (FAPI) - Creating keys using FAPI - Policy using FAPI - Full-disk encryption primitive (FDE) using a TPM - TPM operations for FDE - Advanced TPM Policy usage using tpm2-tools and tpm2-tss - Policy using locality - Policy using the TPM clock and reset - Policy using the TPM's internal NVRAM - Handling external keys using a TPM Please enter the email you have used / will use for beta.ost2.fyi. NOTE: accounts on beta.ost2.fyi are separate from those on p.ost2.fyi as they run on different servers.

Google Docs