DEF CON 33 - Metal-as-a-Disservice: Exploiting Legacy Flaws in Cutting Edge Clouds - Bill Demirkapi

DEF CON 33 - Metal-as-a-Disservice: Exploiting Legacy Flaws in Cutting Edge Clouds - Bill Demirkapi

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 46:18

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video exposes systemic security vulnerabilities in ML-focused bare metal cloud providers, revealing that their claimed security advantages often fail in practice due to improper isolation, outdated protocols, and insufficient firmware reset procedures between customers 1:07.

Key Takeaways:
• Bare metal servers provide direct hardware access for better ML performance but expose significant attack surfaces including firmware, BIOS, BMC, and network vulnerabilities 4:26-4:45
• Providers use systems like Canonical's Metal as a Service (MaaS) that rely on decades-old protocols like PXE boot for provisioning, creating exploitation opportunities 7:22-7:33
• Attackers can establish persistence through malicious boot options, firmware backdoors, or downgrading to vulnerable BIOS versions that bypass security checks 11:15-11:24
• Network isolation failures allow cross-tenant attacks including ARP spoofing, traffic interception, and even DHCP poisoning to hijack provisioning processes 32:04-32:33
• Case studies demonstrated actual providers leaking customer data and allowing access to other tenants' sensitive ML training traffic 41:55-42:37

The security of bare metal cloud services depends entirely on provider implementation, with many smaller ML-focused providers lacking proper security controls that major cloud providers have developed over years 3:53-4:02.

Sources:

  • 1:07 Introduction to ML-focused bare metal providers
  • 4:26-4:45 Attack surfaces in bare metal servers
  • 7:22-7:33(htt

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, this is a talk about bare metal though and for cloud providers. So metal as a disservice and here is here is Bill Demir Kapper. >> Thank you so much everyone for coming out again for another one of my talks. I'm really excited to be back here at Defcon. Um, and yeah, I'm today I'm going to be talking you to you about a wave of systemic vulnerabilities um, in these new cloud providers that have a machine learning focus. So, for some background, my name is Bill Demeruppa and I'm a security researcher with a background in hardware and software as well as the web and cloud. I'm really passionate about security research that I can have an impact at scale and recently I've been working on automating vulnerability discovery with advancements and foundation models for code reasoning. To…