515: Script Boomers
Embedded27 Nov 2025

515: Script Boomers

Nick Kartsioukas joined us to talk about security in embedded systems.

Common Vulnerabilities and Exposures (CVE) is the primary database to check your software libraries, tools, and OSs: cve.org.

Open Worldwide Application Security Project (OWASP, owasp.org) has information on how to improve security in all kinds of applications, including embedded application security. There are also cheatsheets, Nick particularly recommends Software Supply Chain Security - OWASP Cheat Sheet.

Wait, what is supply chain security? Nick suggested a nice article on github.com: it is about your code and tools including firmware update, a common weak point in embedded device security.

Want to try out some security work? There are capture the flag (CTF) challenges including the Microcorruption CTF (microcorruption.com) which is embedded security related. We also talked about the SANS Holiday Hack Challenge (also see Prior SANS Holiday Hack Challenges).

This episode is brought to you by RunSafe Security.

Working with C or C++ in your embedded projects? RunSafe Security helps you build safer, more resilient devices with build-time SBOM generation, vulnerability identification, and patented code hardening. Their Load-time Function Randomization stops the exploit of memory-based attacks, something we all know is much needed. Learn more at RunSafeSecurity.com/embeddedfm.

Some other sites that have good information embedded security:

  • Cybersecurity and Infrastructure Security Agency (CISA) is at cisa.gov and, among other things, they describe SBOMs in great detail

  • National Institute of Standards and Technology (NIST) also provides guidance:


Finally, Nick mentioned Stop The Bleed which provides training on how you can control bleeding, a leading cause of death. They even have a podcast (and we know you like those). Elecia followed up with Community Emergency Response Teams (CERT). Call your local fire department and ask about training near you!

Transcript

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(572)

525: Some Sort of Metal

525: Some Sort of Metal

Dr. Tom Williams spoke with us about robots, ethics, teaching, and books. Then we talked about mines, umpires, water, and more books. Tom is the author of Degrees of Freedom: On Robotics and Social J...

14 Mai 1h 3min

524: This Isn't a Movie

524: This Isn't a Movie

Nathan Jones spoke with us about hardware security, motivation, conference talks, and writing. Nathan wrote an in-depth series of posts about the benefits of superloops vs RTOS: You Don't Need an RTOS...

16 Apr 1h 14min

523: Bad Experience With Donuts

523: Bad Experience With Donuts

Chris and Elecia chat about Leapfrog toys, things they like, large company politics, awards, and open source governance.  The Toy Story 5 Trailer with LilyPad toy which is suspiciously similar to the ...

2 Apr 1h 10min

522: The Information Is In Poop

522: The Information Is In Poop

Sonia Grego speaks with us about a topic no one likes to talk about, but could be used to monitor personal dietary health and widespread disease outbreaks. Toilets! Sonia leads Duke University's Smart...

6 Mar 54min

521: Are You The Tiny Domino?

521: Are You The Tiny Domino?

Kenneth Finnegan entertained us with stories about accidentally contributing to the internet's ability to network. Wondering how the internet works? All those terms about IPv4, IPv6, BGP, OSPF, CDN an...

20 Feb 1h 3min

520: All Sorts of Interesting Facts About Teeth

520: All Sorts of Interesting Facts About Teeth

Chris and Elecia apologize, discuss uses and abuses of chatbots, reach out to an uncertain manager, try to help someone out of their professor's draconian rules, and extol the joys of reading.  Chabot...

6 Feb 58min

519: The Password Is All Zeros

519: The Password Is All Zeros

Mark Omo and James Rowley spoke with us about safecracking, security, and the ethics of doing a bad job. Mark and James gave an excellent talk on the development of their safecracking tools at DEF CON...

23 Jan 1h 6min

518: Nothing We Can Do About Frogs

518: Nothing We Can Do About Frogs

James Cameron spoke with us about programming for and operating a large telescope. The show is a blend of astronomy, engineering on the fly, and weird lady bug habitats.  The Anglo-Australian Telescop...

9 Jan 1h 8min

Populært innen Vitenskap

fastlegen
tingenes-tilstand
jss
dekodet-2
rekommandert
forskningno
sinnsyn
villmarksliv
liberal-halvtime
rss-paradigmepodden
rss-nysgjerrige-norge
rss-zahid-ali-hjelper-deg
tidlose-historier
rss-inn-til-kjernen-med-sunniva-rose
kvinnehelsepodden
rss-rekommandert
nordnorsk-historie
fjellsportpodden
rss-lundqvist-podden
vett-og-vitenskap-med-gaute-einevoll