Sign in

Joe FitzPatrick

@securelyfitz.bsky.social
2.1K followers 202 following 34 posts

Trainer and Researcher, SecuringHardware.com

PostsRepliesMedia
Joe FitzPatrick @securelyfitz.bsky.social · 02/09/2026
Details and registration: www.register.cansecwest.com/csw26/applie...
register.cansecwest.com
Applied Physical Attacks by Joe FitzPatrick at CanSecWest 2026 — CanSecWest 2026 Registration
This is a four-day crash course in rapid prototyping for hardware hacking. You'll build upon the basics you already covered in an introductory hardware hacking course and will design and assemble, fro...
000
Joe FitzPatrick @securelyfitz.bsky.social · 02/09/2026
CanSecWest is only a few weeks away. I don't run my Hardware Implants class very often, and rarely outside the USA, so if you want to take it, this might be your last chance for at least a year. If you're considering it but haven't registered yet, let us know asap!
register.cansecwest.com
Applied Physical Attacks by Joe FitzPatrick at CanSecWest 2026 — CanSecWest 2026 Registration
This is a four-day crash course in rapid prototyping for hardware hacking. You'll build upon the basics you already covered in an introductory hardware hacking course and will design and assemble, fro...
165
Joe FitzPatrick @securelyfitz.bsky.social · 29/07/2026
Looking forward to seeing tons of folks at Black Hat and DEFCON. Here's a not-so-brief list of where to find me: securinghardware.com/upcoming/BHD...
securinghardware.com
Black Hat and Defcon, 2026 - Securing Hardware
This is where I should be through most of Black Hat and Defcon. If you happen to find me elsewhere at these times, please direct me to the right place!
020
Reposted by Joe FitzPatrick
Thaís @barbieauglend.bsky.social · 23/07/2026
Started packing for #Teardown2026 ! Come play with Oscilloscopes on Friday (www.crowdsupply.com/teardown/por...) and discuss hw security and open source with the amazing @dr.supersat.phd, @securelyfitz.bsky.social, and @synapticrewrite.bsky.social on Sunday (www.crowdsupply.com/teardown/por...)!
hachyderm.io
Crowd Supply (@crowdsupply@hachyderm.io)
302 Posts, 34 Following, 1.33K Followers · Curated crowdfunding for engineers, designers and creators of open source technology. We help bring original, useful, respectful hardware to life.
151
Reposted by Joe FitzPatrick
gojimmypi @gojimmypi.bsky.social · 17/07/2026
Fridays are for Games! My first Doom on ULX4M #FPGA 🟢 Luke Wren's Hazard3 RISC-V 🟢 @securelyfitz.bsky.social Tigard programmer 🟢 Enjoy Digital Lite DRAM 🟢 @intergalaktik.bsky.social ULX4M board 🟢 Lattice ECP5 🟢 John Carmack's Doom Generic 🟢 Wave Share CM4 Carrier All open source ♥️
063
Reposted by Joe FitzPatrick
nyx @nyx.ms · 14/07/2026
one hour until def con workshops open up! PDX friends @securelyfitz.bsky.social, mx, and i are doing UART implants: events.humanitix.com/sat_am_ws6_4... PDX friend @drc3p0.bsky.social is doing their EMF Explorer soldering workshop: events.humanitix.com/fri_pm_ws1_4... don't delay, register today
052
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
End rant, begin shameless plug: Black Hat early registration discounts end tomorrow, and there are a ton of excellent classes available, including my own: blackhat.com/us-26/traini...
blackhat.com
Black Hat
Black Hat
020
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
So - No, my classes do not incorporate AI. Yes, you can 'solve' the labs in my classes faster with some AI assistance. But no, you cannot understand the "why" of the labs in my class if you do.
100
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
However, when you're learning how, AI robs you of the chance to ask those questions, which robs you of the chance to learn what the real questions are. You're no longer getting a transferable academic understanding, just a basic vocational understanding of how to use a tool.
230
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
When you're assessing, attacking, or securing a product, AI tools are really helpful in getting you to the answers you need quicker since it can do a really good job of guessing plausible answers to "why" and plenty of data on "how".
100
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
Understanding "why" is a deeper level of understanding that can be applied to different systems. Your understanding of "why" can be applied to NOR flash, NAND flash, EMMC, Fuses, Mask ROMs, or even cloud storage - even though your "how" of "use flashrom" does not apply.
110
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
The both have pros and cons. Vocational can gloss over implementation. Academic can stop short of providing practical techniques. My goal in training is to teach why. Why do we want to dump firmware? Why does JTAG grant so much privilege? Why is it so hard to secure firmware?
100
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
I see two major approaches to training that I'll refer to as Vocational and Academic. Vocational prioritizes teaching how to do the thing. Academic prioritizes teaching why you want to do the thing.
100
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
I have specifically chosen to NOT include AI in my training. Yes - it's more work for me to re-write a class including AI, and I am avoiding that. But it has more to do with WHY I teach classless, and WHY I choose the format that I do.
110
Joe FitzPatrick @securelyfitz.bsky.social · 21/05/2026
Today's daily @blackhatevents.bsky.social USA training reminder comes to you in rant form: AI is definitely a thing. Fundamentally, it is a tool that may or may not improve your work with trade-offs that may or may not be worth it.
221
Joe FitzPatrick @securelyfitz.bsky.social · 19/05/2026
Not a fan of Vegas? Me either! I'll be running an extended 3-day version of the courses at CODEGATE in Seoul, July 21-23: codegate.org/fairContents...
codegate.org
TRAININGS - CODEGATE
000
Joe FitzPatrick @securelyfitz.bsky.social · 19/05/2026
Early registration for @blackhatevents.bsky.social ends this week - register before the price goes up. The class will be offered both Aug 1-2 and Aug 3-4. blackhat.com/us-26/traini...
blackhat.com
Black Hat
Black Hat
120
Joe FitzPatrick @securelyfitz.bsky.social · 19/05/2026
Having trouble learning hardware hacking from some clanker assistant? You probably need some hands-on time with real hardware. Applied Physical Attacks # 1 is the perfect intro to understand what's going to happen to a hardware device the moment it gets into attacker's hands.
161
Joe FitzPatrick @securelyfitz.bsky.social · 18/05/2026
Disabling consoles and debug ports only goes so far, using these features brings an order of magnitude of hardware security to your devices. If you're new to hardware, pair it w/ Applied Hardware Attacks. Otherwise, Applied Fault Injection pairs nicely as well.
010
Joe FitzPatrick @securelyfitz.bsky.social · 18/05/2026
The clock is ticking! This is the last week for early registration prices at @blackhatevents.bsky.social USA. I have a new class this year: How to use Secure Boot and Encrypted Firmware. blackhat.com/us-26/traini...
163
Joe FitzPatrick @securelyfitz.bsky.social · 08/05/2026
Shameless plug: Video from my LABSCON talk was posted yesterday! www.youtube.com/watch?v=rrgU...
youtube.com
LABScon25 Replay | Connect to the Foreign Entity to Enhance Your User Experience | FitzPatrick
YouTube video by SentinelOne
051
Joe FitzPatrick @securelyfitz.bsky.social · 04/03/2026
I think i might just be in my guanjunx era. My workbench is covered with junk from guangzhou.
100
Joe FitzPatrick @securelyfitz.bsky.social · 04/03/2026
In a sea of nonsense brand names - Is this a marketing genius with a knack for self-deprecating humor from Guangzhou? or a drop shipper who's just honest about the origin and quality of their goods?
product listing page that includes a luggage strap branded "GUANJUNX"
120
Joe FitzPatrick @securelyfitz.bsky.social · 17/02/2026
As I finalize the content for my new class on firmware security, I'd like to know: what questions do you have, or do you think that I should be answering in this course? Let me know here, or submit something anonymous at forms.gle/6oeiFHihBkVs...
061
Joe FitzPatrick @securelyfitz.bsky.social · 06/02/2026
I've got a brand new class in the works! Applied Physical Defenses: Secure Boot and Encrypted Firmware The first time I offer this class will be @blackhatevents.bsky.social in Singapore on April 21-22, more offerings coming soon. blackhat.com/asia-26/trai...
082
Joe FitzPatrick @securelyfitz.bsky.social · 04/11/2025
Post - #supercon sightseeing, I did not go to LACMA expecting to see this, but was glad I had stickers in my pocket a the time...
The treachery of images by Rene Magritte, a painting of a pipe that says "this is not a pipe" in french, hangs on the wall in a museum while a hand holds up a sticker saying "this is not a sticker"
040
Joe FitzPatrick @securelyfitz.bsky.social · 23/09/2025
3) in response to some comments, 'fusing off' the 64 bit isa doesn't mean there's an unused 64 but data path on silicon... it's merely disabling the decoding of amd64 opcodes into the uops that are actually executed on the existing execution units.
020
Joe FitzPatrick @securelyfitz.bsky.social · 23/09/2025
2) it was hilarious the number of senior folks inside Intel who genuinely believed AMD copied amd64 from Intel. As an employee it was an effective way to tell apart the folks who had technical merit vs the folks who just got promoted for drinking the coolaid
111
Joe FitzPatrick @securelyfitz.bsky.social · 23/09/2025
Awesome post, thanks for cataloging all that. A few thoughts: 1) ia64/itanium was actually an incredible success if you measure it not by sales but by it completely neutralizing all the RISC alternatives (which of course may have also happened without itanium, but it definitely helped)
210
Reposted by Joe FitzPatrick
Volatility @volatilityfoundation.org · 19/09/2025
#FTSCon Speaker Spotlight: Joe FitzPatrick (@securelyfitz.bsky.social) is presenting “Rethinking DMA Attacks with Erebus” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
015
Joe FitzPatrick @securelyfitz.bsky.social · 13/08/2025
hey! Thanks for the video since i couldn't be in there for it. I'm not sure if you heard it, but over in track two, we all yelled out "Great Talk Micah" at the same time hoping you'd hear it. I think the last second of your video captured the "Great Tal..." of it! www.youtube.com/watch?v=KFYy...
youtube.com
"We are currently clean on OPSEC": The Signalgate Saga (DEFCON 33)
YouTube video by Micah Lee
110
Reposted by Joe FitzPatrick
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 23/06/2025
@notnextjen.bsky.social tops the list of people who have enabled me to grow as a person & professional. She’s the best person to strategically work towards company goals while effortlessly handling the gnarliest security crisis comms. Hire Jennifer Wood if you “take security very seriously.”
0197
Reposted by Joe FitzPatrick
Thaís @barbieauglend.bsky.social · 20/06/2025
Thanks @securelyfitz.bsky.social for not only supporting @blackhoodie.bsky.social with words but also donating **hardware** (all students got a hardware hacking kit which incl. Tigard, Bitmagic, and various cool tools) and helping us carry boxes, setting up the workstations, and cleaning up!!
042
Reposted by Joe FitzPatrick
Catherine @whitequark.org · 24/05/2025
implemented a script for #GlasgowInterfaceExplorer that lets you discover the connectivity of any IC with JTAG boundary scan, provided you can give the IC an arbitrary stimulus (here done by using a glasgow output connected to a needle point probe)
28422
Joe FitzPatrick @securelyfitz.bsky.social · 02/12/2024
and now i notice the typo...
050
Joe FitzPatrick @securelyfitz.bsky.social · 02/12/2024
"brace yourself" meme with the text "Brace Yourself! This cyber monday we have saving so big....  that telling you about them is a transactional communication exempted by the can-spam act from your prior opt-out"
2112
Joe FitzPatrick @securelyfitz.bsky.social · 27/11/2024
This was at the Cyber Crime Gala - meme warfare edition, at labscon in sept. I got a second run of it on Halloween at hackaday supercon.
010
Joe FitzPatrick @securelyfitz.bsky.social · 26/11/2024
i see a grain of rice in there!
3140
Joe FitzPatrick @securelyfitz.bsky.social · 22/11/2024
Lol. Sometimes @dcuthbert.bsky.social scares me. Yeah, hauling the PnP machine to vegas was a pain but well worth it. Thank goodness for small desktop-sized machines. My favorite part was taking a picture of 6 people all standing around taking video of it assembling their boards.
220
Joe FitzPatrick @securelyfitz.bsky.social · 23/05/2023
I'm most excited about the rapid prototyping/hardware implants classed, because I updated them and I'm going to bring a pick&place machine to help assemble the implants we build.
120
Joe FitzPatrick @securelyfitz.bsky.social · 23/05/2023
My first post! I've enjoyed the social media cleanse since stopping twitter use in November, but went back today to try and monetize the platform by pitching training. I've got 4 classes coming up at Black Hat, early reg ends friday: www.blackhat.com/us-23/training/sch…
190