Boot Security Mastery Conference 2026

Kamil Wcisło

Hello. I’m Kamil Wcisło, a Systems Engineer specializing in Cloud-Native Embedded Systems and my project, MekOps stands for Microservices, Embedded, and Kernels Operations.

In the modern tech landscape, there is a significant divide. Cloud engineers treat infrastructure as infinite and disposable. Embedded engineers treat hardware as static and specific. I would like to introduce an engineering philosophy that applies the scalability, observability, and orchestration of the Cloud to the rigid, constrained and multi-architectural reality of bare metal.

I build tools that allow physical hardware to be managed with the same agility as a Kubernetes cluster, without sacrificing the performance of C and Rust. To build the next generation of edge computing, you cannot just be an embedded engineer, and you cannot just be a cloud architect. You must own the stack from the Kernel (NuttX/Linux/Rust/C) to the Microservice (Go/Wasm) and finally Operations (Kubernetes).


Session

09-25
12:30
30min
Where the Chain of Trust Goes Dark: Extending Verified Boot to Signed Wasm Workloads on Microcontrollers
Kamil Wcisło

Verified boot is a solved-on-paper problem: a hardware root of trust measures and authorizes each stage up to the application. But on edge devices that fetch and execute dynamic workloads — OTA firmware modules, plugins, updatable logic — the trust chain typically terminates at the application image. Everything the application loads afterward runs unverified. For a fleet of internet-facing microcontrollers, that is the entire attack surface that matters, and it sits outside the boot-security envelope.

GPN-T Main Room