2026-09-17 –, Main
Secure-boot projects often end up with a zoo of nearly-identical bootloader images for development, factory, and field use with each variant adding more risk.
In this lightning talk, I present barebox's Security Policy support, which facilitates adapting securely to each lifecycle stage and how the state transition can be controlled via eFuses, device-bound unlock tokens or hardware-rooted storage.
Ahmad joined the kernel team at Pengutronix in 2018 to work full-time on furthering Linux world domination. He does so by helping automotive and industrial customers build embedded Linux systems based on the mainline Linux kernel.
Having a knack for digging in low-level guts, his tasks include hardware enablement, Linux driver development and boot loader porting.
Ahmad is a contributor to a number of open-source projects, including the Linux kernel and the barebox boot loader.