Boot Security Mastery Conference 2026

Lance R. Vick

Security Engineer with over 20 years of experience in waiting on operating systems to compile. Former magician, PC repair tech, street entertainer, trucker, day laborer, telemarketer, web developer, tractor salesman, and burger flipper.

Best known for not owning a smartphone, compromising Japanese hotel robots, finding weak entropy flaws across widely used software, software supply chain security publicity stunts, social activism, and implanting random tech in his body.

Actual specialties include Linux infrastructure security, software supply chain security, cryptographic key management, hardware security modules, secure enclaves, remote attestation, vulnerability assessment & mitigation, PII protection, and web application hardening.

Founder of #!, a decentralized hackerspace, and Distrust, a FOSS-focused high-risk security engineering firm. Previously led sysadmin and security engineering efforts at Accesso, Pebble, BitGo, and Turnkey.

Talk to him about decentralization, social issues, mechanical puzzles, plants, weird animals, lockpicking, home manufacturing, homesteading, or anything even remotely related to security and threat modeling.

Relevant: https://distrust.co https://caution.co https://hashbang.sh https://lance.dev https://stagex.tools


Session

09-24
10:30
30min
Verifiable Computing: Connecting trust from bootstrap, to firmware, to runtime
Lance R. Vick

The session will explore current work by our team and others in verifiable computing, from bootstrap to compiler to firmware to runtime. We seek to demonstrate current best efforts to verify what code is running on a remote machine, and promising ideas and efforts to take it even further.

We will cover the current state of reproducible and bootstrappable firmware and runtime build infrastructure via StageX, multi-hardware attestation work through BootProof, building a stack that effectively trusts no single person or computer. This setup, which we refer to as verifiable computing, is critical for high security and privacy use cases such as provably private inference, VPNs, private API proxies, signing oracles, etc. Further we seek to be able to take SBOMs much further, proving every line of code that compiled every line of code all the way back to a small bit of human reviewable machine code.

We will also talk about the gaps. Such as why the Ada programming language remains the biggest blocker to verifiable firmware on Intel systems, what unverifiable binary blobs still exist, and what can be done about it.

GPN-T Main Room