Published Jan 13, 2020

Rick Altherr

Join Bryan Cantrill and Jess Frazelle in a compelling conversation with Rick Altherr as they explore the transformative impact of open source firmware on device management, the fascinating challenges of firmware bugs, and the essential role of security in protecting cloud infrastructure amidst evolving standards.
Episode Highlights
On The Metal logo

Popular Clips

Episode Highlights

  • Discovery

    Rick Altherr, a firmware expert, shares insights into discovering vulnerabilities through reverse engineering. He explains how understanding the capabilities of BMC chips and using tools like Wireshark and Ghidra are crucial in identifying potential flaws. Rick's discovery of the USBAnywhere vulnerability in Supermicro BMCs highlights the importance of scrutinizing firmware for security gaps.

    The early that there is something wrong was an hour of work and it really involved wireshark, and that's about it.

    ---

    This vulnerability exposed 47,000 servers to potential exploitation, emphasizing the critical need for vigilance in firmware security 1 2 3.

       

    Security

    System firmware security is a complex challenge, as Rick Altherr explains, due to outdated standards and insufficient security practices. He notes that many BMCs are vulnerable because they rely on outdated protocols like IPMI, which lack robust security features. The transition to newer standards like Redfish is slow, leaving many systems exposed.

    The entire model of security is like, you can't have perfect security. It doesn't exist.

    ---

    Rick emphasizes the need for a proactive security mindset, urging companies to evaluate their threat models and prioritize firmware security 4 5 6.

       

    Cloud

    In the cloud infrastructure, firmware plays a pivotal role in maintaining security and efficiency. Rick Altherr discusses how the shift to cloud-based systems has changed the security landscape, with multitenancy increasing the complexity of managing vulnerabilities. He highlights the need for secure firmware practices to prevent potential breaches in cloud environments.

    The assumption is the firmware is the first thing that runs.

    ---

    Rick stresses that as cloud systems evolve, so must the strategies for securing firmware, ensuring that vulnerabilities are addressed before they can be exploited 2 4 7.

Related Episodes