Sustainability of the x86 Insecurity Model

No ratings

Presented at BSidesBudapest 2019 by

In today's ever evolving cybersecurity landscape, some organizations are starting to get the grasp of their individual threat profiles and associated attack surfaces that they have to invest time and effort in. Vulnerable software is a problem that we as an industry have been trying to deal with for a long time. There are no perfect solutions but there are many smart people tackling the issues there; doing code audits or performing security assessments, dare I say penetrating testing with an independent team or contractor is something that is definitely on the radar of competent organizations. With some of the industries leading minds on the effort, we've come to develop mitigations against entire classes of vulnerabilities via solutions such as pointer authentication, shadow stacks, control flow integrity checks (CFI) and the like. In this talk, I will tackle what I perceive to be the largest and least well understood attack surface there is in today's organizations, x86 platform security and out of band management systems such as Intel's management engine and AMD's platform "security" processor.