BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.osfc.io//osfc-2026//speaker//WWVYQZ
BEGIN:VTIMEZONE
TZID:Europe/Berlin
BEGIN:DAYLIGHT
DTSTART:20250917T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:[Open Mic] Payload MM: Fixing A coreboot Secure Boot Vulnerability
  With A New SMM Design - Benjamin Doron
DTSTART;TZID=Europe/Berlin:20260917T153000
DTEND;TZID=Europe/Berlin:20260917T155000
DTSTAMP:20260924T222444Z
UID:pretalx-osfc-2026-HHVLPX@talks.osfc.io
DESCRIPTION:UEFI Secure Boot is an important feature that secures the root
  of trust. When configured correctly\, it ensures that your kernel boots t
 he way that *you* want\, without malicious modifications. In coreboot\, it
 's made possible by the SMMSTORE feature.\n\nBut there's a problem: SMMSTO
 RE was developed for basic functionality\, not security. This talk is abou
 t the security vulnerability in  the coreboot implementation of Secure Boo
 t that's caused by decoupling implementation-level details\, like verifica
 tion\, from performing the SPI write in coreboot\, and how we fixed it by 
 allowing part of UEFI into SMM to make this atomic again.
LOCATION:Main Room // Grote Zaal
URL:https://talks.osfc.io/osfc-2026/talk/HHVLPX/
END:VEVENT
END:VCALENDAR
