Ripple20 is a series of zero-day vulnerabilities discovered in a widely used low-level TCP/IP software library developed by Treck, Inc and disclosed by JSOF in June 2020. This session focuses on the original research process used to identify and pinpoint the Ripple20 vulnerabilities, their variants, and some attempts to piece together the historical timeline showing how the original software library changed over time. This was a complex process of reverse engineering multiple devices simultaneously, working in parallel on many different levels. In this session we will describe how we reverse engineered the devices simultaneously, using comparative techniques to confirm each point. We will explain an interesting outcome of the supply chain ripple effect, and how it is now possible to find a vulnerability affecting hundreds of devices for near zero effort.Shlomi Oberman is an experienced security researcher and leader with over a decade of experience in security research and product security. He has spoken internationally and his research has been presented in industry conferences such as CodeBlue Tokyo and Hack-In-The-Box as well as other conferences. He is also an experienced teacher, training researchers and engineers in Embedded Exploitation and Secure Coding, as well as an organizer of local community cyber-security events. Shlomi has the unique advantage of a broad technical understanding of the Security Field as well as deep knowledge of an attacker's mindset.Moshe Kol is a wickedly talented security researcher and the finder of the Ripple20 vulnerabilities. Moshe has a B.Sc. in Computer Science from the Hebrew University of Jerusalem and is currently pursuing his master's degree. He has many years of networking and security research experience working for the MOD where he honed his skills originally developed at home - as he was led by sheer curiosity into the world of reverse engineering and security research.Ariel Schön is an experienced security researcher with unique experience in embedded and IoT security as well as vulnerability research. Ariel is a veteran of the IDF Intelligence Corps, where he served in research and management positions.