
DEF CON 33 - Metal-as-a-Disservice: Exploiting Legacy Flaws in Cutting Edge Clouds - Bill Demirkapi
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 46:18
The video exposes systemic security vulnerabilities in ML-focused bare metal cloud providers, revealing that their claimed security advantages often fail in practice due to improper isolation, outdated protocols, and insufficient firmware reset procedures between customers 1:07.
Key Takeaways:
• Bare metal servers provide direct hardware access for better ML performance but expose significant attack surfaces including firmware, BIOS, BMC, and network vulnerabilities 4:26-4:45
• Providers use systems like Canonical's Metal as a Service (MaaS) that rely on decades-old protocols like PXE boot for provisioning, creating exploitation opportunities 7:22-7:33
• Attackers can establish persistence through malicious boot options, firmware backdoors, or downgrading to vulnerable BIOS versions that bypass security checks 11:15-11:24
• Network isolation failures allow cross-tenant attacks including ARP spoofing, traffic interception, and even DHCP poisoning to hijack provisioning processes 32:04-32:33
• Case studies demonstrated actual providers leaking customer data and allowing access to other tenants' sensitive ML training traffic 41:55-42:37
The security of bare metal cloud services depends entirely on provider implementation, with many smaller ML-focused providers lacking proper security controls that major cloud providers have developed over years 3:53-4:02.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, this is a talk about bare metal though and for cloud providers. So metal as a disservice and here is here is Bill Demir Kapper. >> Thank you so much everyone for coming out again for another one of my talks. I'm really excited to be back here at Defcon. Um, and yeah, I'm today I'm going to be talking you to you about a wave of systemic vulnerabilities um, in these new cloud providers that have a machine learning focus. So, for some background, my name is Bill Demeruppa and I'm a security researcher with a background in hardware and software as well as the web and cloud. I'm really passionate about security research that I can have an impact at scale and recently I've been working on automating vulnerability discovery with advancements and foundation models for code reasoning. To…