BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.3mdeb.com//bsmconf//talk//RHXQSM
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsmconf-RHXQSM@cfp.3mdeb.com
DTSTART;TZID=CET:20260924T143000
DTEND;TZID=CET:20260924T150000
DESCRIPTION:This talk examines the practical experience of implementing and
  evaluating\nfwupd HSI on the Gigabyte MZ33-AR1\, a server platform runnin
 g Dasharo\nopen-source firmware based on coreboot and EDKII. The platform 
 reaches HSI-2\nwith all requirements for HSI-4 met - a strong baseline - y
 et several attributes\nremain out of reach for various reasons. SPI replay
  protection\, for instance\,\nis unavailable due to the SPI flash chip cho
 sen in the board design rather\nthan any AMD-specific limitation. Other ga
 ps are more directly tied to AMD\nplatform specifics: non-trivial interact
 ions between HSI test tooling and\nsuperuser privileges\, and incorrect up
 stream interpretation of suspend-to-idle\nsupport. These cases illustrate 
 how the gap between what HSI tests\nfor and what AMD silicon currently exp
 oses to firmware creates friction for\nboth developers and end users tryin
 g to interpret their security scores.\n\nThe goal is to give firmware engi
 neers and security practitioners a clear\npicture of where HSI on AMD stan
 ds today\, what is blocking progress\, and what\na more complete AMD secur
 ity attestation story could look like as the\nopen-source firmware ecosyst
 em matures.
DTSTAMP:20260801T203227Z
LOCATION:GPN-T Main Room
SUMMARY:Host Security ID (HSI) on AMD servers today and tomorrow - Michał 
 Żygowski
URL:https://cfp.3mdeb.com/bsmconf/talk/RHXQSM/
END:VEVENT
END:VCALENDAR
