YoVDO

Firmware Security - Why It Matters and How You Can Have It

Offered By: linux.conf.au via YouTube

Tags

linux.conf.au Courses Cybersecurity Courses Code Quality Courses System Security Courses Firmware Development Courses coreboot Courses Firmware Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore firmware security in this 45-minute conference talk from linux.conf.au. Delve into the importance of firmware security and its impact on overall system security. Learn about recent vulnerabilities in system management mode, firmware-level hardware initialization scripts, and management engine compromises. Discover the latest advancements in firmware security research and their applications to projects like Coreboot and Libreboot. Gain insights into balancing security with the freedom to run desired software on your system. Understand the attack surface for firmware, vulnerability mitigation strategies, and the significance of firmware updates. Examine options for compatibility and advanced users in improving firmware security.

Syllabus

Intro
Just what is firmware?
Just what is code?
Why do we care about bugs in firmware?
What's the attack surface for firmware?
Where is firmware?
Welcome to System Management Mode
Not all runtime firmware is SMM
never touch untrusted data
Vulnerability mitigation
don't write bugs
But is it just about code quality?
How can we reduce attack surface?
Does Coreboot inherently save us?
What about the Management Engine? • Run the latest firmware
Firmware updates are important
Options for compatibility
Options for more advanced users
Options for super-advanced users
In summary


Taught by

linux.conf.au

Related Courses

Architecture 4031: x86-64 Reset Vector: coreboot
OpenSecurityTraining2 via Independent
Bootstrapping Systems With Open Source Firmware
Hack In The Box Security Conference via YouTube
Hardware Backdooring is Possible
nullcon via YouTube
Baring the System - New Vulnerabilities in SMM of Coreboot and UEFI Based Systems
Recon Conference via YouTube
Open Source Firmware
media.ccc.de via YouTube