Search papers, labs, and topics across Lattice.
This study analyzes the security and maintenance practices within the TianoCore community, which is responsible for a reference implementation of UEFI firmware. By surveying and interviewing a diverse group of stakeholders, including firmware vendors and security experts, the authors uncover significant deficiencies in current firmware development workflows. The findings reveal critical opportunities for enhancing security through the adoption of memory-safe technologies and increased automation, which could bolster the overall integrity of UEFI firmware maintenance.
Major gaps in firmware security practices could leave the TianoCore community vulnerable, but targeted improvements could significantly enhance UEFI firmware integrity.
We investigate the software security and maintenance practices adopted by stakeholders in the TianoCore community and identify opportunities to improve firmware development workflows. We conduct a survey and a limited interview study with participants representing independent firmware vendors, original equipment manufacturers, security experts, firmware developers, and academic researchers. This open-source development community maintains a reference implementation for the core of the UEFI firmware. We highlight important gaps in the current state of firmware development within the TianoCore ecosystem and identify key areas in which improved security practices, greater adoption of memory-safe technologies, and increased automation of manual processes could strengthen the maintenance and security of the UEFI firmware.