BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.recon.cx//recon-2026//speaker//AMSRFC
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-recon-2026-SZE7UX@cfp.recon.cx
DTSTART;TZID=EST:20260621T163000
DTEND;TZID=EST:20260621T170000
DESCRIPTION:Mixed Boolean-Arithmetic (MBA) obfuscation has drawn substantia
 l work in both construction and simplification. Yet the conversation often
  conflates distinct problems: linear MBA results read as general\, restric
 ted-operator techniques read as full-space solutions\, benchmarks built by
  the same techniques they evaluate. Progress is real\, but much of it has 
 happened inside a narrow region of a much larger design space.\n\nThis tal
 k is a benevolent rant: an attempt to map the space well enough to ask the
  right questions\, including ones whose answers may be unwelcome (infeasib
 ility\, hard limits). It organizes the discussion around three: what we bu
 ild\, what we break\, what we don’t know (and probably can’t)\, and ar
 gues the third is larger than the literature treats it.\n\nOn the construc
 tion side\, we attempt to lay out a formal hierarchy of expressions\, sepa
 rate the operators used to build an expression from those targeted by simp
 lification\, and look at how identity equivalences are generated (iterativ
 ely\, compositionally\, otherwise).\n\nOn the simplification side\, once a
 n MBA expression is in hand\, much of what real binaries contain is reacha
 ble with existing tools: not because the problem is solved\, but because c
 onstructions in the wild align with how current attacks decompose them. Th
 e real difficulty lies in expression retrieval: MBA split across blocks or
  functions\, destructured by optimizers\, mangled by lifters\, and in gene
 ral entangled with virtualization and other obfuscation transformations.\n
 \nWe close on foundational obstacles: normal forms\, what “simpler” ev
 en means. We observe that stronger constructions sit in the unexplored par
 t of the map (with no reason to expect current tools would handle them)\, 
 and ask what we’d need to push past that\, with some opinionated takes o
 n directions worth pursuing.
DTSTAMP:20260916T093413Z
LOCATION:Grand Salon Opera
SUMMARY:Mixed Boolean-Arithmetic Obfuscation: What We Build\, What We Break
 \, and What We Can’t - Arnau Gàmez i Montolio
URL:https://cfp.recon.cx/recon-2026/talk/SZE7UX/
END:VEVENT
END:VCALENDAR
