515: Script Boomers
Embedded27 Nov 2025

515: Script Boomers

Nick Kartsioukas joined us to talk about security in embedded systems.

Common Vulnerabilities and Exposures (CVE) is the primary database to check your software libraries, tools, and OSs: cve.org.

Open Worldwide Application Security Project (OWASP, owasp.org) has information on how to improve security in all kinds of applications, including embedded application security. There are also cheatsheets, Nick particularly recommends Software Supply Chain Security - OWASP Cheat Sheet.

Wait, what is supply chain security? Nick suggested a nice article on github.com: it is about your code and tools including firmware update, a common weak point in embedded device security.

Want to try out some security work? There are capture the flag (CTF) challenges including the Microcorruption CTF (microcorruption.com) which is embedded security related. We also talked about the SANS Holiday Hack Challenge (also see Prior SANS Holiday Hack Challenges).

This episode is brought to you by RunSafe Security.

Working with C or C++ in your embedded projects? RunSafe Security helps you build safer, more resilient devices with build-time SBOM generation, vulnerability identification, and patented code hardening. Their Load-time Function Randomization stops the exploit of memory-based attacks, something we all know is much needed. Learn more at RunSafeSecurity.com/embeddedfm.

Some other sites that have good information embedded security:

  • Cybersecurity and Infrastructure Security Agency (CISA) is at cisa.gov and, among other things, they describe SBOMs in great detail

  • National Institute of Standards and Technology (NIST) also provides guidance:


Finally, Nick mentioned Stop The Bleed which provides training on how you can control bleeding, a leading cause of death. They even have a podcast (and we know you like those). Elecia followed up with Community Emergency Response Teams (CERT). Call your local fire department and ask about training near you!

Transcript

Episoder(567)

520: All Sorts of Interesting Facts About Teeth

520: All Sorts of Interesting Facts About Teeth

Chris and Elecia apologize, discuss uses and abuses of chatbots, reach out to an uncertain manager, try to help someone out of their professor's draconian rules, and extol the joys of reading.  Chabot...

6 Feb 58min

519: The Password Is All Zeros

519: The Password Is All Zeros

Mark Omo and James Rowley spoke with us about safecracking, security, and the ethics of doing a bad job. Mark and James gave an excellent talk on the development of their safecracking tools at DEF CON...

23 Jan 1h 6min

518: Nothing We Can Do About Frogs

518: Nothing We Can Do About Frogs

James Cameron spoke with us about programming for and operating a large telescope. The show is a blend of astronomy, engineering on the fly, and weird lady bug habitats.  The Anglo-Australian Telescop...

9 Jan 1h 8min

517: A Direct, Sensible Podcast

517: A Direct, Sensible Podcast

Nathan Jones and Chris Svec give Chris and Elecia their 2025 performance review.  Donations went to Elevate Tutoring, an organization that provides funding and support to low-income and first-generati...

2 Jan 1h 1min

516: Voices From the Cataclysms of the Universe

516: Voices From the Cataclysms of the Universe

Sophi Kravitz joined us to talk about art, science, and engineering.  You can see Messages from Space on Sophi's website /sophikravitz.com). A subset of the artwork had a short stay for a demo at Chab...

12 Des 202558min

514: Just Turn Off All the Computers

514: Just Turn Off All the Computers

Philip Koopman joined us to talk about embedded systems becoming embodied and intelligent. We focus on the safety considerations of making an intelligent and embodied device.  Phil's new book is Embo...

14 Nov 20251h 10min

513: I'm Sorry You Learned Something

513: I'm Sorry You Learned Something

Jason Turner of C++ Weekly and Empty Crate spoke with us about the joy of puzzles, the changing directions of an interesting career, and the C++ programming language. I mean, of course we talked about...

30 Okt 20251h 17min

Populært innen Vitenskap

fastlegen
tingenes-tilstand
rekommandert
jss
rss-rekommandert
sinnsyn
tomprat-med-gunnar-tjomlid
villmarksliv
fjellsportpodden
forskningno
rss-paradigmepodden
rss-overskuddsliv
pod-britannia
tidlose-historier
dekodet-2
rss-skogkurs-podden
rss-nysgjerrige-norge
vett-og-vitenskap-med-gaute-einevoll
kvinnehelsepodden
hva-er-greia-med