Open Source Firmware Conference
osfc.io
osfc.io
I'm beyond impressed with the hard work and passion of its participants. Many of them have worked tirelessly for years on advancing the state of open source firmware in the industry. Some of them have been at it for decades.
Everyone I've spoken with at the event clearly recognize how critical open source firmware is to ensuring platform reliability, resiliency and user control.
I'm gonna assume this is PC firmware based on the list of players, but I haven't been able to find any conclusive information on the website.
Super annoying when groups like this use an extremely generic term for something very specific and just assume the entire world knows what they mean.
The conference's scope is open source firmware in general, as implied by its name.
> I'm gonna assume this is PC firmware based on the list of players, but I haven't been able to find any conclusive information on the website.
The landing page lists ARM as one of the sponsors. The same page also features a list of projects that are represented at the conference. Quotes from their landing pages follow:
- coreboot is ... on modern computers and embedded systems.
- Trusted Firmware provides a reference implementation of secure software for Armv8-A, Armv9-A and Armv8-M.
- The OpenBMC project is a Linux Foundation project whose goal is to produce a customizable, open-source firmware stack for Baseboard Management Controllers (BMCs).
- "oreboot for ARM", "oreboot for RISC-V HiFive Unleashed"
- Welcome to TianoCore, the community supporting an open source implementation of the Unified Extensible Firmware Interface (UEFI).
- u-bmc is a Linux OS dist ... tailor made for baseboard management controllers.
- U-Boot mentions on their landing page too many architectures and vendors to list here, but here's a few: ARC, M68K, MIPS, Xtensa.
[0] https://www.osfc.io/2021/talks/on-hubris-and-humility-develo...
[1] https://www.osfc.io/2022/talks/i-have-come-to-bury-the-bios-...
Main Room OSFC 2022 Opening Event
Christian Walter , Philipp Deppenwiese Open firmware on your infrastructure, not only for hyperscalers.
Erwan Velu Talk details: Open firmware on your infrastructure, not only for hyperscalers. Introduction to VBE - Verified Boot for Embedded
Simon Glass Talk details: Introduction to VBE - Verified Boot for Embedded Tillitis Key - A USB security key inspired by measured boot and DICE
Fredrik Stromberg , Sasko Simonovski , Michael 'MC' Cardell Widerkrantz The “Thing” Around Your System Firmware
Christian Walter , Subrata Banik Talk details: The “Thing” Around Your System Firmware Protecting TPM Commands from Active Interposers
Jordan Hand Talk details: Protecting TPM Commands from Active Interposers FirmwareBleed: The industry failures to adopt SMM mitigations introduced years ago
Alex Matrosov , Philipp Deppenwiese Talk details: FirmwareBleed: The industry failures to adopt SMM mitigations introduced years ago I have come to bury the BIOS, not to open it: The need for holistic systems
Bryan Cantrill Talk details: I have come to bury the BIOS, not to open it: The need for holistic systems Linux as a UEFI bootloader and kexecing windows
Trammell Hudson Talk details: Linux as a UEFI bootloader and kexecing windows How Min Platform led to Max coreboot; a case study
ronald g. minnich Talk details: How Min Platform led to Max coreboot; a case study
And finally, if there's something different you would like to see at OSFC, submit a talk for OSFC 2024!
Secondly, these events looks like their geared toward the private sector, rather than enthusiasts. Why would I want to invest my time in contributing to a problem that is already made worse by commercial endeavors that seem to want to take control away from the user?
* https://ecc2017.com/schedule-location has the list of 2017 with gems like: DDR3 on Sandy Bridge, reversing Mediatek MT8173, reversing x86 microcode.
2016, with video links: https://www.coreboot.org/Coreboot_conference_San_Francisco_2...
2014-2015 don't have video, I think.
If you want to see talks about that "critical topic right now for" you, or even work done in that area, the surest way to get that is to put in the effort yourself.
Maybe the shout-out on this platform encourages somebody (e.g. you?) to present on the subject next year - that would be a win in my book.
The people and projects surrounding the OSFC has been working tirelessly for many years on changing things for the better. I can personally attest to the fact that the people involved are incredibly passionate about open source firmware.
Making firmware open source benefits vendors AND users. It serves commercial interests AND software freedom.
I don't mean to nitpick, but people that actually care about the future of technology and want to make things better usually talk in specific terms rather than throwing out unspecific terminology.
That said: 15 years of activity is a lot of work to unpack in "specific terms", so "unspecified terminology" that still provides a rough overview it is.
How about list of open firmware(preferably consumer grade, big corps can get it anyway) that you helped or developed?
And if it is so good, why more and more hardware needs closed firmware?
As for "why more and more hardware needs closed firmware": In 2005, which PC started from open source firmware, outside select data center deployments?
If you want something 'specific' then I would point you to the Open Compute Project that has now basically mandated that certified servers allow consumers to install alternative fireware. That required a lot of effort and lobbying.
At the same time creating a community of users and vendors that enable new platforms before they are even released. Go look at the coreboot git to see this work.
The lobbying of the community has lead to AMD next generation boot firmware, OpenSil to be open source. Again, this didn't come out of no-where.
Thank you. Now that sounds like it's more up my ally.
https://www.osfc.io/archive/2022/
You can also view past talks.
It also spreads awareness so people can attend the conference next year.
Even in a security context where on one hand it's true that the tiniest pinhole is all it takes, it's also true that there is no such thing a no pinholes, and yes, 80% coverage, even 10% coverage, is better than 0% coverage.
It's a goal and an ideal not an absolute.
When you organize a conference on a location, you are using what they have on site or at best your laptop is hooked in. You have way too much to worry about to bring all your own hardware and to build out the entire media infrastructure conference in a hotel or convention space or wherever you are holding the event. That’s assuming you’re even allowed to access the areas in systems that would allow you to implement your own!
That is an unbelievably laborious task that is unreasonable to put on basically any group. At best weeks of work/installs on top of all the other massive logistic issues you’re handling. If they have a Windows terminal for you to show your presentation, you’re not going to rebuild everything from the ground up just so you can show some static images on open source software/machines. It’s just not reasonable.
That tells me more about you than it does about them. You must walk through your life extremely carefully not to do things that are inconsistent with each other.
If you rent a venue a lot of the tech needed for a conference is already going to be there — and for such a conference they will not have a ton of choices. Secondly open hardware is not very established in the conference hardware space. The reason for that are multiple, but one has to do with the fact that most of the gear requires extremely specialized build chains or equipment and you'd have to compete with decades of R&D and optimized manufacturing processes.
Your open source SM58 is going to be more expensive and less reliable unless you invest decades into it. To get out an okay microphone. Can you tell me why anybody should in your opinion be doing that in their spare time?
So maybe there is someone out there who enjoys going through a ton of prototypes to get something reliable out.
But the issue I think this is going to have is how reproducable that is going to be for your followers. I think in open source there is a spectrum: one the one side you have things like most software or simple standard-parts open hardware projects. On the other side you have things like an open source marble statue, where you still need to bring all the knowledge of how to make the marble statue — draw a circle, draw the rest of the owl and all that.
A microphone with complex coil winding and gluing a micron-thin membrane to a coil is going to be somewhere inbetween.
What exists btw. are condensor mics, but there you need to buy the membrane-assembly yourself.
How much of the actual video recording equipment was coming with free firmware — probably none — does not change the fact that these are people improving the situation rather than just accepting that the hardware you buy is at the mercy of the original vendor.