Package Tampering: Injecting jack in the box.

No ratings

Presented at ROOTCon 2013 by

Often overlooked for being too common (ubiquitous), boring and dispensable (unsexy), little have we thought that product packages are potential vectors of attack. For a progressive security mind, it can be considered as one of the weakest links in the product supply chain. Examples of targets are (but, of course, not limited to) personal letters and/or memos, communication equipment, and computer software and/or hardware among others. In bypassing the packages, access to the aforementioned items can lead to gathering of vital information or “trojaning” the software and installation of alien hardware components or replacement thereof in the communication and computer equipment to conduct snooping, remote admin, or other parasitic activities. This topic aims; 1.) to introduce a new subject on physical security for RootCon 2.) to provide a general view on tampering, giving special attention to package tampering for this presentation 3.) to set the stage for more tampering topics in the future.