Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chase Schultz -- AppSec and Hardware

31 min27 april 2018

Om avsnittet

Where does application security end when software controls bootloaders, firmware, processors, and connected devices? Chase Schultz joins Chris for a wide-ranging discussion of the boundary between AppSec and hardware security. They examine secure coding in embedded systems, trusted boot, firmware signing, coprocessor supply chains, ASLR, and the no-execute bit before unpacking Meltdown and Spectre. Chris explains how speculative execution and processor caches created paths to sensitive memory, while Chase connects the mitigations to defense in depth and threat modeling. The episode shows that familiar software-security practices still matter near the hardware, even when vulnerabilities ultimately require changes to operating systems, microcode, or silicon.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chase Schultz:
Chase Schultz on LinkedIn

Mentioned in this episode:
Meltdown and Spectre
U-Boot
Docker

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Where AppSec meets hardware
01:44 Chase Schultz’s security origin story
06:23 Old AppSec problems in new connected devices
07:47 Microarchitecture attacks and processor optimizations
08:48 Secure coding for hardware and firmware
11:20 Coprocessor supply chains and bootloaders
14:24 Trusted boot and firmware signing
16:37 ASLR, no-execute, and hardware defenses
17:20 How Meltdown and Spectre work
21:46 Speculative execution and access to memory
23:29 Kernel memory, containers, and cloud impact
24:46 Mitigating flaws that live in processors
26:11 Address space layout randomization
28:18 Could threat modeling have found the problem?
30:44 Closing thoughts

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.