EPISODE · Apr 27, 2018 · 31 MIN
Chase Schultz -- AppSec and Hardware
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Where does application security end when software controls bootloaders, firmware, processors, and connected devices? Chase Schultz joins Chris for a wide-ranging discussion of the boundary between AppSec and hardware security. They examine secure coding in embedded systems, trusted boot, firmware signing, coprocessor supply chains, ASLR, and the no-execute bit before unpacking Meltdown and Spectre. Chris explains how speculative execution and processor caches created paths to sensitive memory, while Chase connects the mitigations to defense in depth and threat modeling. The episode shows that familiar software-security practices still matter near the hardware, even when vulnerabilities ultimately require changes to operating systems, microcode, or silicon.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chase Schultz:→ Chase Schultz on LinkedInMentioned in this episode:→ Meltdown and Spectre→ U-Boot→ DockerFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Where AppSec meets hardware01:44 Chase Schultz’s security origin story06:23 Old AppSec problems in new connected devices07:47 Microarchitecture attacks and processor optimizations08:48 Secure coding for hardware and firmware11:20 Coprocessor supply chains and bootloaders14:24 Trusted boot and firmware signing16:37 ASLR, no-execute, and hardware defenses17:20 How Meltdown and Spectre work21:46 Speculative execution and access to memory23:29 Kernel memory, containers, and cloud impact24:46 Mitigating flaws that live in processors26:11 Address space layout randomization28:18 Could threat modeling have found the problem?30:44 Closing thoughts
Embed this episode
What this episode covers
Where does application security end when software controls bootloaders, firmware, processors, and connected devices? Chase Schultz joins Chris for a wide-ranging discussion of the boundary between AppSec and hardware security. They examine secure coding in embedded systems, trusted boot, firmware signing, coprocessor supply chains, ASLR, and the no-execute bit before unpacking Meltdown and Spectre. Chris explains how speculative execution and processor caches created paths to sensitive memory...
Ready to play
Chase Schultz -- AppSec and Hardware
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.