Boot Security Mastery Conference 2026

Beyond "Trust Me": Closing the Firmware Due-Diligence and Patching Loop
2026-09-25 –, GPN-T Main Room

The UEFI specification still opens with a promise to preserve the existing ecosystem: evolutionary rather than revolutionary, built on existing investment. That consensus holds, and nobody wants to break the installed base. But the requirements arriving now from cloud providers, hyperscalers, and operators of sovereign infrastructure ask for what it was never designed to deliver: compute whose trustworthiness is owner-controlled, verifiable from the root of trust to the handoff to the operating system, and reproducible by more than one party. Trustworthy by evidence, not by assertion.


The legacy consensus cannot be held as it is and cannot be discarded. The work is to bring legacy systems into the new era and show what a properly built boot chain looks like, from a single board to a rack.

This talk states where 3mdeb commits for that era. Firmware code volume is rising, and its quality is not, in proprietary and open stacks alike; a static chain asks you to trust all of it. Dynamic roots of trust for measurement bound how much of that code you must trust, and reference integrity manifests with attestation turn measurements into provenance. BenchRack closes the loop: a finding becomes a patch, the patch is validated on a physical twin, the deployment is observed, and the evidence is a by-product of the same run.

Attendees will leave knowing what 3mdeb ships next across PET, Dasharo, and Zarhus, and what it will ask of the ecosystem around it.

Piotr Król is an open-source firmware enthusiast and the founder of 3mdeb, established in March 2015. Rooted in the hacker ethos of collaboration and transparency, his work drives innovation in firmware resilience, platform security, and digital sovereignty.

At 3mdeb, Piotr leads projects such as Zarhus OS, a Yocto-based embedded Linux distribution, Dasharo, a downstream coreboot project focused on trustworthiness, privacy, and liberty, and PET (Pace Enterprise Training), a platform for advanced technical education. These initiatives support open development, transparency, the right to repair, and the long-term maintenance of open-source firmware-based systems.

Piotr’s technical focus spans Root of Trust, Secure/Verified/Measured Boot, TPM, UEFI, EDK II, coreboot, U-Boot, Yocto, and Linux. He regularly speaks at major industry events, including FOSDEM, Xen Developer Summit, and the Platform Security Summit, advocating for open-source solutions in platform security.

Committed to community knowledge-sharing, Piotr is also a trainer with OpenSecurityTraining2, contributing free and open learning resources to strengthen the global open-source firmware ecosystem.

This speaker also appears in: