Safeguarding UEFI Ecosystem - Firmware Supply Chain is Hardcoded
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the complexities of supply chain security in the UEFI ecosystem through this 41-minute Black Hat conference talk. Delve into the challenges posed by multiple parties involved in firmware code development, including Intel/AMD's reference code and core frameworks from AMI, Phoenix, and Insyde. Understand why hardware platform vendors contribute less than 10% to the UEFI system firmware code base and the implications of this reality. Examine how vulnerabilities can be discovered not only in platform vendor codebases but also within reference code, potentially impacting the entire ecosystem. Learn about the varying patch cycles across vendors, the extended periods vulnerabilities can remain unpatched, and the difficulties in verifying fixes due to inconsistent patching methods. Gain insights from experts Alexander Tereshkin, Alexander Matrosov, and Adam Zabrocki on safeguarding the UEFI ecosystem and addressing the hardcoded challenges in firmware supply chain security.
Syllabus
Safeguarding UEFI Ecosystem: Firmware Supply Chain is Hard(coded)
Taught by
Black Hat
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network