BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.3mdeb.com//bsmconf//speaker//9DRENG
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsmconf-7FSW9B@cfp.3mdeb.com
DTSTART;TZID=CET:20260924T111000
DTEND;TZID=CET:20260924T114000
DESCRIPTION:Enabling Intel Boot Guard is hard. Enabling it via a firmware u
 pdate on laptops already in customers' hands is something most firmware en
 gineers would rather not think about - because the operation is irreversib
 le\, the recovery options if something goes wrong range from "painful" to 
 "nonexistent\," and the consequences fall on people who have no idea any o
 f this is happening.\n\nThis talk is a war story. At 3mdeb\, we shipped Bo
 ot Guard enablement as a field update for a production laptop line - handl
 ing key provisioning\, IBB definition\, fuse-blowing sequencing\, and the 
 update delivery mechanism\, all while knowing that a mistake meant a fleet
  of unrecoverable machines. This talk covers what we got right\, what we g
 ot wrong\, what the Intel documentation doesn't prepare you for\, and what
  process changes we made after the parts that hurt.\n\nAttendees will leav
 e with a concrete understanding of the risks specific to field provisionin
 g (as opposed to factory provisioning)\, a framework for building confiden
 ce before an irreversible operation\, and an appreciation for why key mana
 gement is the part that deserves the most paranoia.
DTSTAMP:20260729T065328Z
LOCATION:GPN-T Main Room
SUMMARY:Fusing in the Wild: Enabling Intel Boot Guard on Deployed Laptops -
  Michał Kopeć
URL:https://cfp.3mdeb.com/bsmconf/talk/7FSW9B/
END:VEVENT
END:VCALENDAR
