Boot Security Mastery Conference 2026

Fusing in the Wild: Enabling Intel Boot Guard on Deployed Laptops
2026-09-24 , GPN-T Main Room

Enabling Intel Boot Guard is hard. Enabling it via a firmware update on laptops already in customers' hands is something most firmware engineers would rather not think about - because the operation is irreversible, the recovery options if something goes wrong range from "painful" to "nonexistent," and the consequences fall on people who have no idea any of this is happening.

This talk is a war story. At 3mdeb, we shipped Boot Guard enablement as a field update for a production laptop line - handling key provisioning, IBB definition, fuse-blowing sequencing, and the update delivery mechanism, all while knowing that a mistake meant a fleet of unrecoverable machines. This talk covers what we got right, what we got wrong, what the Intel documentation doesn't prepare you for, and what process changes we made after the parts that hurt.

Attendees will leave with a concrete understanding of the risks specific to field provisioning (as opposed to factory provisioning), a framework for building confidence before an irreversible operation, and an appreciation for why key management is the part that deserves the most paranoia.

Michał Kopeć is a firmware engineer at 3mdeb, an enthusiast of open source and a low level hacker.

At 3mdeb, he has worked on open-source firmware for laptops, network appliances and servers. His recent work includes Intel Boot Guard enablement, Dasharo platform ports, and LinuxBoot integration. He has also worked on UEFI based firmware, discrete GPU enablement, Linux kernel drivers, and Intel TXT enabling.

In his spare time he hacks on coreboot ports for machines in his posession and on Linux graphics drivers.