Updated
Updated · WIRED · Jul 31
Defcon Unveils 27,000 Badges With Huang's Open Source Baochip-1x Token
Updated
Updated · WIRED · Jul 31

Defcon Unveils 27,000 Badges With Huang's Open Source Baochip-1x Token

3 articles · Updated · WIRED · Jul 31

Summary

  • Defcon’s 27,000 badges will double as detachable hardware security tokens, marking the first major distribution of Andrew Huang’s Baochip-1x after only a small developer release.
  • The 3-year-old chip project is built to make security verifiable: Huang published the OS, firmware, RISC-V core and crypto code, and packaged the silicon for infrared inspection against the public design.
  • The removable module supports FIDO authentication, one-time passwords and password management, with a low-resolution QR-scanning camera designed to avoid practical photo capture or storage.
  • Built on a 350 MHz RISC-V processor with 2 MB of SRAM and 4 MB of RRAM, the chip adds secure boot, a true random number generator and memory meant to resist physical extraction.
  • Huang says the token should withstand attacks costing tens of thousands of dollars, but expects Defcon hackers to find zero-days that could help harden future versions.

Insights

Can a fully transparent open-source chip survive the world's largest hacker conference without exposing critical flaws?
Could infrared-scannable silicon finally eliminate the threat of hidden backdoors in our most sensitive digital devices?