Boot Security Mastery Conference 2026

Filip Gołaś

Hello, I'm Filip Gołaś, an Embedded Firmware Developer at 3mdeb, finishing a master's in informatics specializing in machine learning.
In my spare time I keep a small homelab, sharpen knives, play airsoft, and repair my stuff, since I believe in owning what I bought and paid for. I wouldn't trade in my pet parrot for a better-behaved one, I'd train it, so why replace stuff I can repair?


Session

09-24
11:50
30min
How nested EDK2 capsules enable verified open-source firmware updates
Filip Gołaś

The presentation will introduce the audience to the concept of EDK2 capsule updates
and how a secure verified update can be performed using nested capsules.
The main topics include:

  • What EDK2 Capsule Updates are
  • Why capsule verification was not feasible before with EDK2 as a coreboot payload
  • How nested capsules allow the verification of all of the update data
  • How the implementation looks like in Dasharo firmware (demo)
GPN-T Main Room