515: Script Boomers
Embedded27 Marras 2025

515: Script Boomers

Nick Kartsioukas joined us to talk about security in embedded systems.

Common Vulnerabilities and Exposures (CVE) is the primary database to check your software libraries, tools, and OSs: cve.org.

Open Worldwide Application Security Project (OWASP, owasp.org) has information on how to improve security in all kinds of applications, including embedded application security. There are also cheatsheets, Nick particularly recommends Software Supply Chain Security - OWASP Cheat Sheet.

Wait, what is supply chain security? Nick suggested a nice article on github.com: it is about your code and tools including firmware update, a common weak point in embedded device security.

Want to try out some security work? There are capture the flag (CTF) challenges including the Microcorruption CTF (microcorruption.com) which is embedded security related. We also talked about the SANS Holiday Hack Challenge (also see Prior SANS Holiday Hack Challenges).

This episode is brought to you by RunSafe Security.

Working with C or C++ in your embedded projects? RunSafe Security helps you build safer, more resilient devices with build-time SBOM generation, vulnerability identification, and patented code hardening. Their Load-time Function Randomization stops the exploit of memory-based attacks, something we all know is much needed. Learn more at RunSafeSecurity.com/embeddedfm.

Some other sites that have good information embedded security:

  • Cybersecurity and Infrastructure Security Agency (CISA) is at cisa.gov and, among other things, they describe SBOMs in great detail

  • National Institute of Standards and Technology (NIST) also provides guidance:


Finally, Nick mentioned Stop The Bleed which provides training on how you can control bleeding, a leading cause of death. They even have a podcast (and we know you like those). Elecia followed up with Community Emergency Response Teams (CERT). Call your local fire department and ask about training near you!

Transcript

Jaksot(569)

490: Wait Until Physics Has Happened

490: Wait Until Physics Has Happened

Nikolaus Correll spoke with us about robots, teaching robotics, and writing books about robots. Nikolaus is a Professor of Computer Science at the University of Colorado, see his lab website (or his ...

28 Marras 20241h 5min

489: Constructive Cat

489: Constructive Cat

Chris and Elecia discuss her origami art show, ponder PRs for solo developers, attempt to explain GDB debugging, and make a to-do list for getting rid of Kanga. Elecia is having an Origami Octopus Ga...

16 Marras 20241h 1min

488: Two Slices of Complimentary Bread

488: Two Slices of Complimentary Bread

Adrienne Braganza Tacke spoke with us about her book Looks Good To Me: Constructive Code Reviews. It is about how to make code reviews more useful, effective, and congenial. Adrienne's book is availa...

31 Loka 20241h 10min

487: Focus on Fizzing

487: Focus on Fizzing

Chris and Elecia chat about simulated robots, portents in the sky, the futility of making plans, and grad school. A problem with mics led us to delay the show with Shimon Schoken from Nand2Tetris (co...

17 Loka 20241h 5min

486: A Nice Rainbow Dream

486: A Nice Rainbow Dream

Antoine van Gelder spoke to us about making digital musical instruments, USB, and FPGAs. Antoine works for Great Scott Gadgets, specifically on the Cynthion USB protocol analysis tool that can be use...

3 Loka 202454min

485: Conversation Is a Kind of Music

485: Conversation Is a Kind of Music

Alan Blackwell spoke with us about the lurking dangers of large language models, the magical nature of artificial intelligence, and the future of interacting with computers. Alan is the author of Mo...

20 Syys 20241h 17min

484: Collecting My Unhelpful Badge

484: Collecting My Unhelpful Badge

Chris and Elecia talk to each other about setting aside memory in a linker file, printing using your debugger, looking around a new code base, pointers as optimization, choosing processors, skill tree...

5 Syys 20241h 2min

483: An Ion of the Highest Fidelity

483: An Ion of the Highest Fidelity

Rick Altherr spoke with us about high-speed control, complicated systems, and making quantum computers. If you want to know more about building quantum computers, take a listen to Rick's MacroFab epis...

23 Elo 20241h 1min

Suosittua kategoriassa Tiede

tiedekulma-podcast
rss-mita-tulisi-tietaa
rss-duodecim-lehti
rss-poliisin-mieli
mielipaivakirja
docemilia
radio-antro
filocast-filosofian-perusteet
rss-ylistys-elaimille
university-of-eastern-finland
utelias-mieli
rss-ranskaa-raakana
rss-astetta-parempi-elama-podcast
rss-metsantuntijat-podcast
rss-tiedetta-vai-tarinaa
rss-lihavuudesta-podcast