Security Weekly Productions

Below the Surface (Video) - The Supply Chain Security Podcast

A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions.

Author

Security Weekly Productions

Category

Technology

Podcast website

eclypsium.com

Latest episode

Aug 14, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

SCRM and Supply Chain Security Up and Down the Stack - Steve Orrin - BTS #11 Video 31.05.2023

Supply Chain threats and industry / government initiatives like EO 14028 are driving a deeper understanding and a set of requirements for applying supply chain risk management (SCRM) and increased transparency (ex. SBOM) across the software ecosystem up and down the stack. Platform and system firmware present unique challenges for supply chain assurance from the depths of the stack.   Segment Reso...

Learning About Firmware Security - Xeno Kovah - BTS #10 Video 17.05.2023

Firmware security is a deeply technical topic, that's hard to get started in. In this talk, Xeno will discuss some past work in firmware security, and how he has organized resources such as a low level timeline (with over 300 talks), and free MOOC classes, to help teach people about firmware security. Segment Resources: https://ost2.fyi https://darkmentor.com/timeline.html   Show Notes: https://se...

Accidentally Learning about Security: From Firmware to the Cloud - Brian Richardson - BTS #9 Video 03.05.2023

Brian Richardson didn't start out wanting to do marketing or computer security... but after starting his career as a BIOS programmer, he tripped and fell into technical marketing (aka "Binary to English translator"). Brian's here to talk about the importance of hardware & firmware security in a SaaS world. Segment Resources: https://www.youtube.com/watch?v=I2FwiEH6dg4 https://www.youtube.com/watch...

Introducing fwupd and the Linux Vendor Firmware Service - Richard Hughes - BTS #8 Video 19.04.2023

The LVFS is a project used by over 130 different vendors, from all positions of the supply chain. It decompresses, decompiles, then analyses firmware looking for issues, and then automatically builds a SBoM for each download.   Segment Resources: https://fwupd.org/ https://github.com/fwupd   Show Notes: https://securityweekly.com/bts8  

Firmware Pulse - What is Happening Right Now - Nicholas Starke - BTS #7 Video 05.04.2023

Discuss current events in firmware security, such as the techniques utilized in BlackLotus. We will compare Baton Drop with Grub2 capabilities.   Segment Resources: https://starkeblog.com/   Show Notes: https://securityweekly.com/bts7

Armoring the Unified Extensible Firmware Interface (UEFI), from Standards to Open Source - Vincent Zimmer - BTS #6 Video 22.03.2023

This session will provide an overview of the history of host firmware, or BIOS, focusing on the arc of the Unified Extensible Firmware Interface. It will include the development of defenses like UEFI Secure Boot and the challenges in scaling assurance across a broad ecosystem. It will close on works-in-progress and opportunities to build upon the school-of-hard-knocks learnings in this space.   Sh...

Community Insights: Supply Chain Threats, Critical Firmware Attacks, and more! - BTS #5 Video 08.03.2023

In this edition of Below The Surface, we discuss insights Scott collected from various members of our community. Topics include supply chain threats, critical firmware attacks, and more! We also welcome special guest Tyler Robinson! View the full report here: https://eclypsium.com/2022/12/13/december-firmware-threat-report/   This segment is sponsored by Eclypsium. Visit https://securityweekly.com...

Supply Chain Threats, Vulnerable Drivers, OpenSSL Vulnerabilities, and more! - BTS #4 Video 22.02.2023

Paul and Scott talk about supply chain threats, vulnerable drivers, leaked source code and keys, and cover what we know about the OpenSSL 3.x vulnerability.   This segment is sponsored by Eclypsium. Visit https://securityweekly.com/eclypsium  to learn more about them!   Show Notes: https://securityweekly.com/bts4

Inevitable Attacks, UEFI Vulnerabilities, and more! - BTS #3 Video 08.02.2023

This month Scott and Paul discuss the inevitability of attacks against certain sectors, UEFI vulnerabilities galore and so much more! Get the full report here:  https://eclypsium.com/2022/10/03/september-firmware-threat-report/    This segment is sponsored by Eclypsium. Visit https://securityweekly.com/eclypsium  to learn more about them!    Show Notes: https://securityweekly.com/bts3

Root of Trust (RoT) - BTS #2 Video 26.01.2023

Paul and Scott break down the Root of Trust (RoT) and other highlights from the August 2022 Below The Surface Threat Report: https://eclypsium.com/2022/08/31/august-firmware-threat-report/   This segment is sponsored by Eclypsium. Visit https://securityweekly.com/eclypsium to learn more about them!   Show Notes: https://securityweekly.com/bts2

Firmware & Supply Chain Security - BTS #1 Video 25.01.2023

Paul Asadoorian and Scott Scheferman sit down to discuss this month's firmware and supply chain threat report. We cover some of the history and latest developments regarding Secure Boot security research, the threats we face securing the firmware supply chain, and some insights into threat actors targeting firmware. View the full report here: https://eclypsium.com/2022/07/27/july-firmware-threat-r...

Listen to the Below the Surface (Video) - The Supply Chain Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.