Videos / Defcon / Tom Paul: Private Keys Hidden in Firmware and Software

Tom Paul: Private Keys Hidden in Firmware and Software

Duration: 40min 5sec Type: Presentation (lecture) Playlist: 43 of 146 in Defcon
A DEF CON 31 talk on how private keys, certificates, and cryptographic secrets are often left inside firmware and software, where they can be extracted through binary analysis.

The talk presents real-world examples from products by Netgear, Fortinet, and Dell. The researcher demonstrates techniques for finding keys in firmware, including analyzing PEM files, extracting certificates from obfuscated archives, and uncovering hidden cryptographic mechanisms.

In the most critical case, Dell software was found to use a static AES key to connect to VMware vCenter. This key is shared across all customers, allowing attackers to decrypt credentials.

The talk concludes with a discussion on improving key management, developer education, and eliminating the practice of storing secrets in binaries.