YoVDO

Safeguarding UEFI Ecosystem - Firmware Supply Chain is Hardcoded

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Supply Chain Security Courses

Course Description

Overview

Explore the complexities of supply chain security in the UEFI ecosystem through this 41-minute Black Hat conference talk. Delve into the challenges posed by multiple parties involved in firmware code development, including Intel/AMD's reference code and core frameworks from AMI, Phoenix, and Insyde. Understand why hardware platform vendors contribute less than 10% to the UEFI system firmware code base and the implications of this reality. Examine how vulnerabilities can be discovered not only in platform vendor codebases but also within reference code, potentially impacting the entire ecosystem. Learn about the varying patch cycles across vendors, the extended periods vulnerabilities can remain unpatched, and the difficulties in verifying fixes due to inconsistent patching methods. Gain insights from experts Alexander Tereshkin, Alexander Matrosov, and Adam Zabrocki on safeguarding the UEFI ecosystem and addressing the hardcoded challenges in firmware supply chain security.

Syllabus

Safeguarding UEFI Ecosystem: Firmware Supply Chain is Hard(coded)


Taught by

Black Hat

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network