515: Script Boomers
Embedded27 Marras 2025

515: Script Boomers

Nick Kartsioukas joined us to talk about security in embedded systems.

Common Vulnerabilities and Exposures (CVE) is the primary database to check your software libraries, tools, and OSs: cve.org.

Open Worldwide Application Security Project (OWASP, owasp.org) has information on how to improve security in all kinds of applications, including embedded application security. There are also cheatsheets, Nick particularly recommends Software Supply Chain Security - OWASP Cheat Sheet.

Wait, what is supply chain security? Nick suggested a nice article on github.com: it is about your code and tools including firmware update, a common weak point in embedded device security.

Want to try out some security work? There are capture the flag (CTF) challenges including the Microcorruption CTF (microcorruption.com) which is embedded security related. We also talked about the SANS Holiday Hack Challenge (also see Prior SANS Holiday Hack Challenges).

This episode is brought to you by RunSafe Security.

Working with C or C++ in your embedded projects? RunSafe Security helps you build safer, more resilient devices with build-time SBOM generation, vulnerability identification, and patented code hardening. Their Load-time Function Randomization stops the exploit of memory-based attacks, something we all know is much needed. Learn more at RunSafeSecurity.com/embeddedfm.

Some other sites that have good information embedded security:

  • Cybersecurity and Infrastructure Security Agency (CISA) is at cisa.gov and, among other things, they describe SBOMs in great detail

  • National Institute of Standards and Technology (NIST) also provides guidance:


Finally, Nick mentioned Stop The Bleed which provides training on how you can control bleeding, a leading cause of death. They even have a podcast (and we know you like those). Elecia followed up with Community Emergency Response Teams (CERT). Call your local fire department and ask about training near you!

Transcript

Jaksot(567)

512: What if I Didn't Stop?

512: What if I Didn't Stop?

Katherine "Smalls" Connell spoke with us about making thin and flexible circuits, making stretchable electronics, and running a successful Kickstarter. Katherine's Kickstarter: Sprite Lights LED Body...

16 Loka 20251h 5min

511: Forty Trillion Divides

511: Forty Trillion Divides

Chris and Elecia talk about the show overflowing to another bit, fight over vim vs nano, consider awards, discuss writing (and self-motivation), consider linear algebra on AI cores, encourage remote d...

2 Loka 20251h 22min

510: The Secret Chip

510: The Secret Chip

Christina Cyr spoke with us about building cell phones, entrepreneurship, social purpose corporations, awards, lithium recycling, and her interesting career path. We talked about Christina's Cyrcle P...

19 Syys 20251h 4min

509: Swarmed by Engineers

509: Swarmed by Engineers

Steve Hinch wrote a book about engineering, innovation, and business. He shares decades of wisdom gleaned from his career at Hewlett-Packard and Agilent as an engineer, manager, marketing director, an...

5 Syys 20251h 13min

508: Descartes' Demon

508: Descartes' Demon

William Griffin spoke to us about hardware-in-the-loop testing, simulation, terminology, learning complex topics, and books. We don't usually expand upon the show title but Wikipedia has a rabbit hole...

21 Elo 20251h 22min

507: Turn Our Data Into Predators

507: Turn Our Data Into Predators

Chris and Elecia chat about books, courses, alternate podcasts, electronics, statistics, kidnapping Roo, and journaling failures. The Embedded Patreon book club is reading Data-Driven Science and Eng...

7 Elo 20251h 14min

506: How Do I Fit a Whale Into an Apartment Building?

506: How Do I Fit a Whale Into an Apartment Building?

Dmitry Grinberg joined us to talk about running Linux on small microprocessors (physically small and/or 4-bit). Dmitry does this by emulating a MIPS processor. Boot times vary between minutes and days...

25 Heinä 20251h 2min

505: Potato in a Number Field

505: Potato in a Number Field

We spoke with Peter Griffin about Jumperless Breadboards, no-install GUI development, Excel, and puppies. Jumperless Breadboard at CrowdSupply Colab GUI for Jumperless Breadboard Website GUI for ...

10 Heinä 20251h 18min

Suosittua kategoriassa Tiede

rss-mita-tulisi-tietaa
rss-poliisin-mieli
rss-duodecim-lehti
tiedekulma-podcast
rss-lihavuudesta-podcast
utelias-mieli
docemilia
mielipaivakirja
radio-antro
rss-opeklubi
sotataidon-ytimessa
hippokrateen-vastaanotolla
rss-laakaripodi
rss-mental-race
rss-luontopodi-samuel-glassar-tutkii-luonnon-ihmeita
rss-sosiopodi