coreboot Uncovered: BIOS Security, and Vulnerabilities with Matt DeVillier and David Hendricks

  Рет қаралды 688

Nerding Out With Viktor

Nerding Out With Viktor

Күн бұрын

In this comprehensive episode of "Nerding Out with Viktor," we delve into the intricate world of coreboot, a leading open-source BIOS technology. Joining the discussion are Matt DeVillier, also known as Mr. Chromebox, renowned for his contributions to coreboot, first as a community member, and later professionally at Purism and AMD. Also joining is David Hendricks, a seasoned expert with a background at major tech companies like Facebook, Google, and Amazon.
David Hendricks sets the stage by recalling his initial foray into coreboot during his internship with project founder Ron Minnich. He narrates his experiences at Los Alamos National Lab and his pivotal role as the first firmware engineer for Google's Chrome OS team. Matt Devillier shares his journey from a hardware enthusiast to becoming a notable figure in the coreboot community, with a focus on x86-based Chrome OS devices.
The episode dives deep into the mechanics and significance of coreboot, contrasting it with U-Boot and highlighting its varied applications, particularly in Chromebooks and server environments.
A significant segment of the conversation focuses on security within BIOS technology. The experts discuss Secure Boot, differentiate between Google's verified boot and UEFI Secure Boot, and emphasize BIOS control for robust security. They also examine critical BIOS vulnerabilities like LogoFail and PixieFail, underscoring their impact on the security landscape.
Supply chain security emerges as a key topic, with discussions around the importance of transparency and control in the firmware development process. The conversation delves into Software Bill of Materials (SBOMs) and their role in ensuring firmware integrity and trust, reflecting coreboot's commitment to supply chain security.
For organizations contemplating a transition to coreboot, the discussion illuminates the associated challenges and steps, emphasizing the need for early engagement with ODMs and the value of consulting services. The potential of RISC-V in the open hardware field and coreboot's involvement in this evolving area is also explored.
Matt and David conclude the episode with insights into the circular economy and coreboot’s role in extending the lifespan of hardware. They discuss its importance in developing countries and sustainable computing practices.
This episode of "Nerding Out with Viktor" offers a thorough understanding of coreboot, its impact on technology, its crucial role in BIOS security and supply chain integrity, and a vision for the future of BIOS technology and open-source firmware development.
Useful Resources:
Discover more about coreboot (www.coreboot.org), including consultant links (coreboot IBVs), hardware vendors using coreboot, and extensive documentation at coreboot's homepage.
Explore MrChromebox.tech (mrchromebox.tech) for Matt DeVillier's (Mr. Chromebox) custom distribution of coreboot.
Access Converged Security Suite (github.com/9el..., a suite of tools designed for provisioning Bootguard, enhancing the security of your devices.
Utilize goswid (github.com/9el..., a tool for generating Software Bill of Materials (SBOM) within coreboot, ensuring firmware transparency and integrity.
For developers and enthusiasts, find comprehensive information on Chrome OS Devices (www.chromium.o..., including those powered by coreboot, at Developer Information for Chrome OS Devices. Note that almost all recent x86 and ARM models of ChromeOS devices use coreboot, with the exception of the earliest models.

Пікірлер: 7
@Sama_09
@Sama_09 4 ай бұрын
Mr chromebox saved 7 chromeboxes i had !! Made me enter homelab 😂
@timtrout6740
@timtrout6740 5 ай бұрын
Great video, very informative
@eniggma9353
@eniggma9353 3 ай бұрын
nice.
@_f_a_b_s_
@_f_a_b_s_ Ай бұрын
Very interesting Talk and many THANKS to Mr. Chromebox for his great work!
@mr.iot-tech278
@mr.iot-tech278 Ай бұрын
Nice video :) it was interesting to hear the story of coreboot :)
@nerdingoutwithviktor
@nerdingoutwithviktor Ай бұрын
Thank you!
@0xsalfar
@0xsalfar 6 ай бұрын
👌
Heads: Tamper-evident Firmware with User-controlled Keys
1:01:14
Southern California Linux Expo
Рет қаралды 713
37C3 -  Turning Chromebooks into regular laptops
38:55
media.ccc.de
Рет қаралды 70 М.
OYUNCAK MİKROFON İLE TRAFİK LAMBASINI DEĞİŞTİRDİ 😱
00:17
Melih Taşçı
Рет қаралды 12 МЛН
Electric Flying Bird with Hanging Wire Automatic for Ceiling Parrot
00:15
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 11 МЛН
Bike Vs Tricycle Fast Challenge
00:43
Russo
Рет қаралды 101 МЛН
UEFI Boot for Mere Mortals
28:33
FOSDEM
Рет қаралды 3,8 М.
Framework Laptop - We Need More Open Hardware Like This!
9:58
Mental Outlaw
Рет қаралды 271 М.
Exploring the C2PA Standard with Dom Guinard from Digimarc
1:01:03
Nerding Out With Viktor
Рет қаралды 316
Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google
38:03
The Linux Foundation
Рет қаралды 69 М.
25c3: coreboot: Beyond The Final Frontier
50:51
Christiaan008
Рет қаралды 1 М.
First Realtime App With The Golang Platform
1:10:49
TheVimeagen
Рет қаралды 120 М.
coreboot Internals: Aaron Durbin
1:09:34
coreboot.org
Рет қаралды 3,3 М.
OYUNCAK MİKROFON İLE TRAFİK LAMBASINI DEĞİŞTİRDİ 😱
00:17
Melih Taşçı
Рет қаралды 12 МЛН