<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Tom Paul: Private Keys Hidden in Firmware and Software</title>
        <link>https://peertube.eqver.se/videos/watch/89f1c024-25f6-45ef-b9c5-7c65b1247e1c</link>
        <description>A DEF CON 31 talk on how private keys, certificates, and cryptographic secrets are often left inside firmware and software, where they can be extracted through binary analysis. The talk presents real-world examples from products by Netgear, Fortinet, and Dell. The researcher demonstrates techniques for finding keys in firmware, including analyzing PEM files, extracting certificates from obfuscated archives, and uncovering hidden cryptographic mechanisms. In the most critical case, Dell software was found to use a static AES key to connect to VMware vCenter. This key is shared across all customers, allowing attackers to decrypt credentials. The talk concludes with a discussion on improving key management, developer education, and eliminating the practice of storing secrets in binaries.</description>
        <lastBuildDate>Fri, 24 Jul 2026 11:29:40 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.eqver.se</generator>
        <image>
            <title>Tom Paul: Private Keys Hidden in Firmware and Software</title>
            <url>https://peertube.eqver.se/client/assets/images/icons/icon-512x512.png</url>
            <link>https://peertube.eqver.se/videos/watch/89f1c024-25f6-45ef-b9c5-7c65b1247e1c</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.eqver.se/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.eqver.se/feeds/video-comments.xml?videoId=89f1c024-25f6-45ef-b9c5-7c65b1247e1c" rel="self" type="application/rss+xml"/>
    </channel>
</rss>