hosting a workshop themed around repurposing cheap ST-LINK clones (I got two for 14.39 ILS including shipping from Aliexp). The idea is to teach people how to turn them into FIDO2 (Webauthn) hardware tokens which can be used for 2FA on many popular websites (including Github, Google account, Facebook and many more, see dongleauth) or OpenPGP smartcards (can be used for e.g. ssh keys, signing/decrypting e-mail etc). Of course the MCUs (STM32F103 or compatibles) do not feature real tamper-resistance and can be cloned (with considerable effort) given physical access to them but for many threat models that is not problematic. [paul]
Plan of the class:
Ideas to consider: