Boot Security Mastery Conference 2026

Verifiable Computing: Connecting trust from bootstrap, to firmware, to runtime
2026-09-24 –, GPN-T Main Room

The session will explore current work by our team and others in verifiable computing, from bootstrap to compiler to firmware to runtime. We seek to demonstrate current best efforts to verify what code is running on a remote machine, and promising ideas and efforts to take it even further.

We will cover the current state of reproducible and bootstrappable firmware and runtime build infrastructure via StageX, multi-hardware attestation work through BootProof, building a stack that effectively trusts no single person or computer. This setup, which we refer to as verifiable computing, is critical for high security and privacy use cases such as provably private inference, VPNs, private API proxies, signing oracles, etc. Further we seek to be able to take SBOMs much further, proving every line of code that compiled every line of code all the way back to a small bit of human reviewable machine code.

We will also talk about the gaps. Such as why the Ada programming language remains the biggest blocker to verifiable firmware on Intel systems, what unverifiable binary blobs still exist, and what can be done about it.

Lance R. Vick is a co-founder and security engineer at Caution, a verifiable compute company building infrastructure for proving what software is actually running in production. His work spans confidential computing, remote attestation, reproducible builds, software supply-chain security, Linux infrastructure, cryptographic key management, and hardware security.

Previously, Lance led sysadmin and security engineering efforts at Accesso, Pebble, BitGo, and Turnkey. He is also the founder of Distrust, a FOSS-focused high-risk security engineering firm, and #!, a public-access Unix and hacker community that has been operating for over 20 years.

He has spent more than 20 years working on security-critical systems and is particularly interested in connecting trust from hardware and firmware through the operating system and into application runtime.

Talk to him about decentralization, threat modeling, mechanical puzzles, plants, weird animals, lockpicking, home manufacturing, or anything remotely related to security.

Relevant: https://caution.co https://distrust.co https://hashbang.sh https://lance.dev https://stagex.tools