DEF CON 33 - What’s Really in the Box? The Case for Hardware Provenance and HBOMs - Allan Friedman

DEF CON 33 - What’s Really in the Box? The Case for Hardware Provenance and HBOMs - Allan Friedman

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:23

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Hardware supply chains face significant security risks that require transparency through Hardware Bills of Materials (HBOMs), similar to Software Bills of Materials (SBOMs), but with unique challenges for physical components 0:07.

Key Takeaways:
• Hardware supply chains face risks including counterfeits, vulnerabilities, and active tampering during transit that need to be addressed 4:21.
• Government regulations are already being implemented, such as the rule requiring no Chinese components in US cars by 2029 8:03.
• HBOM focuses on security risks for semiconductors and active components, creating a data layer to support risk management similar to SBOMs 9:13.
• Unlike SBOMs, HBOM requires different levels of assurance across sectors, from consumer IoT to aerospace and national security 17:21.

The development of HBOM frameworks is underway, but addressing gaps like hardware-software linking will require international collaboration and possibly AI solutions 22:06.

Sources:

  • 0:07 Speaker introduction and SBOM background
  • 4:21 Hardware supply chain risks
  • 8:03 Government regulations for components
  • 9:13 HBOM focus on security risks
  • 17:21 Different levels of assurance needed
  • 22:06 Gaps and implementation challenges

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

And we're off. All right, welcome everyone. Uh, my name is Alan Freriedman. If you've ever heard of an SBOM, there's a decent chance that's my fault. If you've ever had to make an SBOM, that probably was my fault. And so, I'm sorry about that. Uh I just wrapped up on Friday 10 years as the US government being one of the US government leads for supply chain security and been looking around for what's the next problem that we're going to have to solve together. And I think a big thing that we're going to have to tackle is going to be hardware supply chain and HBO. So oops there we go. What are we going to have to tackle through today? Um, either you could go down to a village and hack some cool stuff or we could talk about security risks and one of the problems that we're going to have to be…