Loading…
June 21-24, 2022
Austin, Texas, USA + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2022 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central Daylight Time (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Tuesday, June 21 • 2:55pm - 3:35pm
Uncovering Software Provenance in Embedded Systems - Ricardo Mendoza, Pantacor

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
With IoT, 5G, and embedded devices becoming a big part of everyone’s daily lives, security should be on everyone’s minds. Security and more importantly trust in our embedded devices are essential for many reasons. Embedded devices have not always had good security with the last several years seeing a significant number of high-profile hacks that could prevent people from widely adopting IoT in their homes. The federal government also signed an executive order signed last year that requires companies selling connected devices must include a SBoM. But SBoMs are only a small part of the story around keeping embedded devices secure and from a developer and operator point of view, the more important issue is knowing that what you are running and deploying are from trusted sources. In this talk, we’ll discuss the security requirements for embedded Linux devices, with a focus on origin determination and how this can (or cannot) be achieved with the existing tools and practices. We’ll then go through a use case to show how all components of an embedded device can be signed, attested and verified with the help of Pantavisor Linux’s “revisions” and then drill down on code signing, and revoking (if necessary) the provenance of malicious and unsigned code on embedded Linux systems.

Speakers
RM

Ricardo Mendoza

CEO, Pantacor
Embedded Linux enthusiast since the early 2000s, and part of previous leadership roles on special projects at Canonical and others, Ricardo brings deep insight into the workings of the connected devices industry, with the intention of shaping the future of embedded Linux. Ricardo... Read More →



Tuesday June 21, 2022 2:55pm - 3:35pm CDT
Room 205 (Level 2)