Boot Security Mastery Conference 2026

Piotr Król

Piotr Król is an open-source firmware enthusiast and the founder of 3mdeb, established in March 2015. Rooted in the hacker ethos of collaboration and transparency, his work drives innovation in firmware resilience, platform security, and digital sovereignty.

At 3mdeb, Piotr leads projects such as Zarhus OS, a Yocto-based embedded Linux distribution, Dasharo, a downstream coreboot project focused on trustworthiness, privacy, and liberty, and PET (Pace Enterprise Training), a platform for advanced technical education. These initiatives support open development, transparency, the right to repair, and the long-term maintenance of open-source firmware-based systems.

Piotr’s technical focus spans Root of Trust, Secure/Verified/Measured Boot, TPM, UEFI, EDK II, coreboot, U-Boot, Yocto, and Linux. He regularly speaks at major industry events, including FOSDEM, Xen Developer Summit, and the Platform Security Summit, advocating for open-source solutions in platform security.

Committed to community knowledge-sharing, Piotr is also a trainer with OpenSecurityTraining2, contributing free and open learning resources to strengthen the global open-source firmware ecosystem.


Sessions

09-24
10:00
25min
Welcome to BSMConf 2026 Day 1
Piotr Król
  • Day 1 event schedule and organization announcements
  • Shout out to the sponsors
GPN-T Main Room
09-24
17:55
5min
BSMConf 2026 - Day 1 closing notes
Piotr Król

Closing notes

GPN-T Main Room
09-25
10:00
10min
Welcome to BSMConf 2026 Day 2
Piotr Król
  • Day 2 event schedule and organization announcements
  • Shout out to the sponsors
GPN-T Main Room
09-25
11:10
30min
Beyond "Trust Me": Closing the Firmware Due-Diligence and Patching Loop
Piotr Król

The UEFI specification still opens with a promise to preserve the existing ecosystem: evolutionary rather than revolutionary, built on existing investment. That consensus holds, and nobody wants to break the installed base. But the requirements arriving now from cloud providers, hyperscalers, and operators of sovereign infrastructure ask for what it was never designed to deliver: compute whose trustworthiness is owner-controlled, verifiable from the root of trust to the handoff to the operating system, and reproducible by more than one party. Trustworthy by evidence, not by assertion.

GPN-T Main Room
09-25
17:55
5min
BSMConf 2026 - Day 2 closing notes
Piotr Król

Closing notes

GPN-T Main Room