> dmcdonald.net / talks > ─────────────────────
Talks & workshops
conference talks, workshops, and short-form research presentations
── upcoming ──────────────────────────────────
Unlocked & Leaked
Modern Dell systems claim a locked BIOS protects against physical attackers, password screen, Secure Boot enforcement, IOMMU-protected DMA, signed firmware updates. We'll show two reasons it doesn't. First: disabling preboot DMA protection by flipping a single NVRAM byte; the BIOS setup screen still cheerfully reports DMA enabled. Second: a bug that lets us pull BIOS passwords out in cleartext. Both attacks reduce to read-modify-write of the SPI flash with a SOIC clip and a cheap programmer. The talk covers the bugs, the tooling, and what it means for deployed Dell hardware.
Thin Client? Thin Crypto
Full disk encryption in enterprise thin clients. Track 2, 11:30 PDT.
── 2026 ──────────────────────────────────────
Unlocked & Leaked
Modern Dell systems claim a locked BIOS protects against physical attackers, password screen, Secure Boot enforcement, IOMMU-protected DMA, signed firmware updates. We'll show two reasons it doesn't. First: disabling preboot DMA protection by flipping a single NVRAM byte; the BIOS setup screen still cheerfully reports DMA enabled. Second: a bug that lets us pull BIOS passwords out in cleartext. Both attacks reduce to read-modify-write of the SPI flash with a SOIC clip and a cheap programmer. The talk covers the bugs, the tooling, and what it means for deployed Dell hardware.
── 2025 ──────────────────────────────────────
IR Ingress
Hands-on workshop covering the IR Ingress hardware: a custom-built NIR emitter that beams modulated infrared through glass facades to trigger wave-to-exit motion sensors from outside a building. Attendees worked through the basic IR primitives with TX/RX breakout modules, then watched the full Rev2 device demonstrated against a bench of commercial exit sensors.
── 2024 ──────────────────────────────────────
Bypassing BitLocker by Sniffing the SPI Bus
Hands-on workshop covering BitLocker encryption circumvention in TPM-only mode. Participants monitored SPI buses with digital logic analysers, extracted TPM data, and mounted and decrypted disks. Targeted at penetration testers, red team operators, and forensic analysts.
Breaking the Shield: Bypassing FortWeb WAFs and Zscaler ZIA
Bypassing IaaS perimeter solutions (FortWeb Cloud WAFs and Zscaler ZIA) via false assumptions about what cloud-vs-traditional infrastructure boundaries actually enforce. Low-tech, easy bypasses that compromise systems sold as managed protection.