Check out Olivier’s best stories, his worst customers, and his tips.

A man in a video game illustrating the cover of our blog article

The Interview 

Olivier Thomas‘ best stories, his worst customers, and his tips.

> How has hardware security changed over the last 20 years?

The biggest change I noticed is the community growing over the years. People were interested in analyzing protocols and performing side channels. Silicon level hacking existed too, but was confidential and limited to few areas such as PayTv. More and more people are now involved in that discipline for various reasons, from forensics to IP litigation cases, and obsolescence management or simply for competition analysis. Conferences followed the same growth with hardware hacking only events — focusing on the research of protocol failures, side channel and non-invasive fault —such as Hardwear.io, to Silicon hacking only events — focusing on extracting information from sample prep or imagery — with PAINE and HARRIS. This trend continues and Silicon hacking definitely is a thing nowadays.

> What motivated you to start Texplained?

Understanding was a big point. When I started my career researching Laser Fault Injection, I could trigger very interesting behaviors without understanding what was really going on. We could also perform fully invasive memory extractions at the time but the amount of circuitry we could Reverse-Engineer was quite limited and the job quite tedious and manual. So when I was given the chance, I started Texplained with the idea of automating the RE pipeline to the point where our tool could be used to write the datasheet of a black box chip using a custom instruction set.

> Which techniques (non-invasive, semi-invasive, invasive) fascinated you the most ?

Good question. I understand the underlying principles behind the different techniques which remove some of their magic. To me, the impressive part is to be able to create a “digital twin” of a circuit, analyze it and perform all these cool techniques based on the gathered knowledge. Going from a physical chip, generating tens of TB of data to create the model, reducing this to few coordinates to know where to modify the chip and to put micro-probing needles, then, gathering GB of data with the needles and formatting them using custom made software to reduce this once again to few KB of usable firmware. That’s kind of cool.

> Which early mistakes taught you the most?

All of them. I used to have a separate lab notebook where I was writing all of my experiments that failed. I had the feeling that they were in a way more valuable than the successful ones and the books were pretty full. I guess making mistakes is part of the RE process and more mistakes equates to more learnings. I do remember though how my colleagues made fun of me for months when I mis-identified a memory back in my early days. I also do remember, again when I was doing LFI, having a daily routine that was preparing 10-20 samples in the morning and killing them all in the afternoon.. Success does not come for free I guess.

> If someone started today, what would be the most important foundations to build first? 

This is a question I often get from people attending Texplained’s training sessions. The first thing would be to have an adequate mindset combining curiosity and dedication. You will fail all the time. Then, I will come back to the training, saying that I always start with the (boring) theory regarding semiconductors. You need to know how it is made (and it’s continuously evolving), how it works, not only the transistors but the architecture of the chips you are interested in. Stay curious and do not read too many books; learning through RE is the best school by far. When preparing a training, a talk, or a customer report, I always try to explain things gradually. You can assume that I discovered much of the stuff through experience. I just try to condensate this for everyone to understand it too, step by step.

> What made your first team so memorable?

There will be so much to say here. I was a young engineer, they were the greatest hackers in their field. Not only was there the shock of discovering invasive techniques and all the required equipments, but getting to know this international team of experts was something. I think there could be a TV show telling their stories and it would be a guaranteed success. The way we were organized can not be described. We were all motivated by the same thing which was the challenge of getting data out of the most secure chips at the time. We would work at any time but also anywhere and that includes bars, yachts, dark lab rooms (for better contrast on the computer screens of course). We would experiment a lot too and do science experiments all the time. We would also enjoy parties together or simply enjoy evenings at the beach.

> What are the strengths of your actual team at Texplained ? 

Several. I have to start with the managing team that is bringing everything together. I feel more at ease solving the problems than running the company. Texplained would not be there if my co-founder was not the one handling the company, the customers and myself. I have to also mention the technical team which is developing ChipJuice as a “true” software. My personal tools are not nice looking, not necessarily easy to use, not well documented. It is great to be able to see and use ChipJuice which is so easy to use and so efficient. The big thing with the team is that we can all rely on each other. There is no heavy hierarchy to fight against or to lose time on. Everyone knows they can propose new things.

> What role does community play in a field as niche as hardware reverse engineering? 

It plays a huge role! Texplained was involved as much as possible with hardware and silicon conferences, giving trainings and lectures. It was important to bring Silicon RE to the light and I hope we had some kind of an impact there. It is also noticeable that the trainings were a growing factor for us as we could talk directly with people that could have an interest. Some of them became customers, some became friends… As the community extends, more and more people are speaking together about Texplained which creates a beneficial feedback loop for us as a company.

The community now extends from Europe to North America and Asia where we start to be more present with Codegate for example this summer. 

> What problem were you trying to solve when designing ChipJuice?

I was trying to understand what was happening during Laser Fault Injection. I also had in mind RE based techniques. These would be non- or semi-invasive techniques based on a prior step of Silicon RE. What if instead of fishing, we would go straight to the point. For example, people are usually scanning the chip surface with a laser to hopefully find a vulnerability. What if you could analyze the Silicon to know where to place the laser instead? More coverage, more possibilities for sure… And this extends to so many techniques.. I started to  have the plan to create a  tool that could make writing datasheets of black box and custom architecture chip possible. I was motivated by science and discovered the real issues that needed to be solved with our customers. 

> What was your biggest blunder in your 13 years as CTO of Texplained?

I remember two things immediately.

The first one was during a training at a chip vendor. I was speaking about shields — which are a protective layer on the chip that are meant to protect against micro-probing— which I disagree with on so many aspects. In these situations, I can find a lot of arguments and this time, I was showing a specific example and said that the design was quite bad. I remember someone raising his hand in the back of the room. I was expecting a question but it was not what happened. I just criticized the design of this person for 10 minutes at least and he just wanted to let me know about it. The best part was that he completely agreed on the fact that the design was bad.

I remember another time giving a training where I used pictures where you could trace signals based on a color. And this time, I asked at the very beginning if someone in the room was color-blind. And that was the case. I felt so bad and so useless as I could not think of a quick fix to help. The best part is that this person was the fastest to solve the assignments entirely!

> What was your biggest fear in Le Lab

It was a smell. The heavy smell of Chlorine. The gas that wants to kill you. It was long ago, the lab I was working in had a separate room for the gas storage, the pumps and all these noisy equipments. The room was narrow and long, moving into it was an experience, not difficult but you had better look where you walked. One access only with a quite heavy door. For some reason, I had to go inside but when I opened the door, the smell immediately burned my nose. So I went out, found a gas mask, took a camera and went back inside to see what was happening. I was calm but I also did not want to stay there too long. I went to the Chlorine bottle directly and I had some kind of a hallucination I think. It was leaking of course, but it was also reacting with the metal bottle itself creating some kind of a crystal structure on the bottle. With fear and the dark, I thought the bottle was sliced open which meant I was standing there in a Chlorine rich environment. This thing being corrosive, I started to expect pain on my skin but it never happened. I understood what was going on with the pictures I quickly took before escaping the room a second time.

The story became almost funny after I called the emergency services. The first squad came and were not well prepared in my opinion. I was standing outside with one of my colleagues explaining to them all of the risks linked to that room. What gas, what equipments could be in the way, etc. but the person in charge stopped our description and went in the room with his squad, wearing leather gloves. We told them it was not working for handling chlorine, they told us they knew their job, ran inside and escaped not long after. Some of them were removing their gloves with a visible urgency. They then called a specialized chemical intervention squad. Lessons learned.

> Your worst anecdotes with a client regarding security?

I can’t think of a truly bad experience but I do remember strange meetings where we found ourselves with my business partner in situations where we did not know what to say any more. Once at a very big security company with a manager that listened to us carefully, to finally conclude “security, we don’t care about it. What only matters is price!”. He left us speechless.
Another time, speaking with a chip designer with extensive experience who told us that the security at his company was there for 20 years and therefore was perfect. I think that security, especially Silicon security, can’t be perfect by nature, that the attacker learning curve is endless and remember, Silicon vulnerabilities, at least for some of them, can’t be patched… Being too confident would be the biggest mistake for the defensive side to me.

> Have you ever upset a customer?

Yes, I did. One of our first customer projects ended up with a weird twist. We were asked by a chip vendor to evaluate in complete black box its latest Secure Element. At the time, I was writing what would become ChipJuice while also performing the chip analysis. That was very stressful and when I entered the room for the closing meeting and realized that it was full, full of developers, security architects, team managers, the pressure went up a notch.
My introduction started with some context. I told right away that my presentation was based on the little I understood of the design and that for sure, they all individually knew more than I did and that they could correct me any time provided I would say things that are wrong.
At the time, we designed a technique to extract the memory content from the device. Something that did not truly rely on a vulnerability, it was there by nature and therefore could not be patched, so I knew that my conclusions were touchy to say the least. And being the one that says he defeated the security of the product in front of so many people that were there physically and remotely on screens comes with a challenge of its own. I could understand they would be pissed, and some were. During the Q&A, one of them told me he was skeptical about my results. It was easy to react on though as I had all necessary data to prove my theories. But that was not enough for the designers and they asked me for more details about how we could bypass some of their counter-measures. They did not like my answer as I simply said I did not notice them, making the counter-measure useless. I remember writing down the counter-measure in my notes at the moment to investigate later which I think did not help the situation.
Hopefully, the vast majority of the people were more intrigued than pissed, so after these little tensions, things cooled down. We had a very good relationship with the vendor and I always had the pleasure to meet the people involved in the project there.

The CEO’s word

Clarisse Ginet

Reading this interview, it really makes me think about everything we went through to get here.

This journey… it has truly been something. It was very stressful at the start, especially when we had to build everything from nothing and convince people that our vision for ChipJuice was possible. I remember many long days and nights where we didn’t know if the technical challenges would ever end.

But it was also so teaching and, honestly, a lot of fun. I am very proud when I see how our team works now. Seeing how we transformed those early, “rough” technical tools into a real professional software like ChipJuice is probably one of our biggest successes. It took a lot of work and some “headaches,” but we did it together.

This adventure has been a bit crazy sometimes, but it’s what made Texplained what it is today. We learned that in silicon security, you can never be too sure of yourself, and that’s why we keep pushing every day.

I’m very happy to share this journey with my partner and with our great team.