Thierry Laurion
Heads maintainer, Accessible Security evangelist, full time Open Source Firmware R&D, linux plumber by need.
Session
LinuxBoot replaces most vendor firmware with a Linux kernel and an initramfs, and is explicitly agnostic about which runtime it uses: u‑root provides a generic Go‑based userland and boot policy toolkit, while Heads is a secure runtime that can be used as the initramfs for LinuxBoot. Heads, in turn, is a firmware distribution that replaces proprietary BIOS/UEFI with coreboot, a Linux kernel and a security‑focused initramfs to bring measured boot and TPM‑based protection to laptops, desktops and servers.
This talk looks at boot chain security in that configuration: Heads as one LinuxBoot implementation, not the reference, and how we can better merge the two worlds instead of keeping them as parallel efforts.