Uploaded August 2026 | Updated September 2026, 2 hours ago
Pedro Umbelino (Liaison, PT)
The 2036–2038 rollover is not a legacy timestamp bug. It is a cross-sector vulnerability class and a global systemic risk, rooted in a pervasive design pattern inherited from the original 32-bit Unix time_t representation. Modern dependency chains amplify this exposure through orphaned firmware, unmaintained toolchains, libraries, userland components, certificate-validity windows, distributed authentication flows, and other long-tail software lifecycle failures. Many production environments cannot be safely tested without emulating upstream Internet dependencies — the same observer effect that malware analysts face when studying complex behavior in isolated sandboxes.
We explain why full-fidelity temporal testing is extremely challenging in production environments. We present our work toward a reference stress-testing framework that CERTs, PSIRTs, and IR teams can begin implementing. We examine discovery workflows, dependency-mapping challenges, early-warning indicators from Bitsight Internet scan data, practical coordination guidelines, and priority mitigation efforts already underway. Drawing on our research and the FIRST Time SIG, we offer concrete next steps organizations can take today, while there is still time to get upstream of this problem. We close with a call to action: the Time SIG needs volunteers. There are two choices — early and late — and we are already almost late. Come join us.
The authors of this session include Trey Darley and Pedro Umbellino.
---
Pedro Umbelino currently holds the position of Principal Research Scientist at Bitsight Technologies and brings over a decade of experience in dedicated security research. His eclectic curiosity has led to the uncovering of vulnerabilities spanning a gamut of technologies, highlighting critical issues in multiple devices and software, ranging from your everyday smartphone to household smart vacuums, from the intricacies of HTTP servers to the nuances of NFC radio frequencies, from vehicle GPS trackers to protocol-level denial of service attacks. Pedro is committed to advancing cybersecurity knowledge and has shared his findings at prominent conferences, including Bsides Lisbon, DEF CON, Hack.lu and RSA.
Trey Darley leads the FIRST Time Security SIG, coordinating international research and remediation efforts related to the 2036–2038 rollover vulnerabilities. He has spent the past decade studying temporal fragility across embedded, cloud, and critical-infrastructure systems, and recently presented the draft technical report for this work at the ITU-T.
A long-standing member of the BruCON and FIRST communities, Trey has served in multiple volunteer roles, including a term on the FIRST Board of Directors, where he co-founded the FIRST Standards Committee. He is recognized for his contributions to open cybersecurity standards such as STIX/TAXII, and for his long association with the Langsec community’s approach to software correctness and input handling. Trey’s patron saints are Grace Hopper, Evi Nemeth, and Paul Erdős. Trey has presented at USENIX, FIRST, BruCON, O'Reilly Security Amsterdam, RSAC, hack.lu, BSides Lisbon, and others.
Pedro Umbelino (Liaison, PT)
The 2036–2038 rollover is not a legacy timestamp bug. It is a cross-sector vulnerability class and a global systemic risk, rooted in a pervasive design pattern inherited from the original 32-bit Unix time_t representation. Modern dependency chains amplify this exposure through orphaned firmware, unmaintained toolchains, libraries, userland components, certificate-validity windows, distributed authentication flows, and other long-tail software lifecycle failures. Many production environments cannot be safely tested without emulating upstream Internet dependencies — the same observer effect that malware analysts face when studying complex behavior in isolated sandboxes.
We explain why full-fidelity temporal testing is extremely challenging in production environments. We present our work toward a reference stress-testing framework that CERTs, PSIRTs, and IR teams can begin implementing. We examine discovery workflows, dependency-mapping challenges, early-warning indicators from Bitsight Internet scan data, practical coordination guidelines, and priority mitigation efforts already underway. Drawing on our research and the FIRST Time SIG, we offer concrete next steps organizations can take today, while there is still time to get upstream of this problem. We close with a call to action: the Time SIG needs volunteers. There are two choices — early and late — and we are already almost late. Come join us.
The authors of this session include Trey Darley and Pedro Umbellino.
---
Pedro Umbelino currently holds the position of Principal Research Scientist at Bitsight Technologies and brings over a decade of experience in dedicated security research. His eclectic curiosity has led to the uncovering of vulnerabilities spanning a gamut of technologies, highlighting critical issues in multiple devices and software, ranging from your everyday smartphone to household smart vacuums, from the intricacies of HTTP servers to the nuances of NFC radio frequencies, from vehicle GPS trackers to protocol-level denial of service attacks. Pedro is committed to advancing cybersecurity knowledge and has shared his findings at prominent conferences, including Bsides Lisbon, DEF CON, Hack.lu and RSA.
Trey Darley leads the FIRST Time Security SIG, coordinating international research and remediation efforts related to the 2036–2038 rollover vulnerabilities. He has spent the past decade studying temporal fragility across embedded, cloud, and critical-infrastructure systems, and recently presented the draft technical report for this work at the ITU-T.
A long-standing member of the BruCON and FIRST communities, Trey has served in multiple volunteer roles, including a term on the FIRST Board of Directors, where he co-founded the FIRST Standards Committee. He is recognized for his contributions to open cybersecurity standards such as STIX/TAXII, and for his long association with the Langsec community’s approach to software correctness and input handling. Trey’s patron saints are Grace Hopper, Evi Nemeth, and Paul Erdős. Trey has presented at USENIX, FIRST, BruCON, O'Reilly Security Amsterdam, RSAC, hack.lu, BSides Lisbon, and others.










