2026-07-25 –, Track 1
The Wink Hub 2 is a 2016 multi-radio home automation hub, which was locked down using High Assurance Boot techniques. This talk will cover my efforts over a period of 3 years to finally run my own code on it - apparently the first person to do so.
The Wink Hub 2 is a 2016 multi-radio home automation hub, originally purchased by myself because of its appearance as a hardware hacking playground - multiple manufacturer radio reference implementations dotted around the board, each with their own programming interface brought out to headers. Due to how easily the prior generation Hub 1 was hacked, the company implemented Freescale/NXP High Assurance Boot v4 techniques to lock the Hub 2 down. These were effective for 10 years to the best of my knowledge - I have seen no reports of anyone else successfully executing their own code on the Hub 2.
This talk will cover my efforts to break the security of the Wink Hub 2, and the lengths to which I went over a three year period to finally execute my own code on this device.
Rogan Dawes is a senior researcher at SensePost and has been hacking since 1998, which, coincidentally, is also the time he settled on a final wardrobe. He used the time he saved on choosing outfits to live up to his colleague’s frequent joke that he has an offline copy of the Internet in his head. Rogan spent many years building web application assessment tools, and is credited as having built one of the first and most widely used intercepting proxies; WebScarab. In recent years, Rogan has turned his attentions towards hardware hacking; and these days many suspect him to be at least part cyborg. A good conversation starter is to ask him where he keeps his JTAG header.
