hack::soho | Back to the Future with Platform Security | Krzysztof Okupski @IOActive
hack::soho | Back to the Future with Platform Security | Krzysztof Okupski  @IOActive
Uploaded September 2024 | Updated September 2026, 1 week ago
Check out Krzysztof Okupski's, IOActive Principal Security Consultant, talk 'Back to the Future with Platform Security,' which was presented at hack::soho in January 2024.

--

ABSTRACT:

In the last decade the industry has seen a significant amount of research released around Intel platform security.

Since the release of CHIPSEC, the industry has had a tool to quickly analyze the Intel platform against a secure baseline for misconfigurations - as a result, it has become more difficult to find misconfigured Intel platforms from major OEMs. As IOActive dove into the platform security realm, it was clear there was a lack of attention and analysis of the AMD platform - given the popularity and the growing market share of the AMD platform, this was unexpected.

Our research started with an overview of how secure boot worked under the hood and exposed the various vulnerabilities and implementation mistakes our team found; also assessing the architectural differences across Intel and AMD that make up for the security of the platforms.

Presenting the details and proof of concepts for the several vulnerabilities found in the targeted platforms; these included unlocked SMRAM regions, SPI flash misconfigurations, as well as memory corruption and race conditions issues in SMM modules. Our efforts led to developing a tool that can be used by end users to quickly verify that their systems are free from common misconfigurations with the AMD platform.

--

Interested in joining us at one of our 'Hack UK' events? Follow our events page to find a local happenings near you! ioactive.com/events
hack::soho | Back to the Future with Platform Security | Krzysztof OkupskiIOActive Freakshow Party- Double Contortion!IOActive Freakshow Party- Gladiator Joust!IOActive Research | NFC Relay Attack - Tesla Y | Josep Pi RodriguezIOActive Smart City Security: Hacking & Securing Smart Cities (webinar)Hack Soho | One more bug : how to secure software | November 2018SoftBanks NAO and Pepper as an espionage toolhack::soho | Secure YAML, Insecure Clusters: Breaking Kubernetes Without Exploits | Simon RobinIOActive | How would a vendor go about getting OCP S.A.F.E. certified?IOActives Freakshow Party- Contortionist!SimpliSafe home security system vulnerability - by Dr Andrew Zonenberg (IOActive)Robots Want Bitcoins To! (Sp.)
IOActive, Inc. |

hack::soho | Back to the Future with Platform Security | Krzysztof Okupski

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER