Skip to content
TrackPodcasts
technologyMar 19, 202638:32

embedded world Recap, New oHFM Standard, & the Importance of Security

About this episode

Send us Fan Mail

On this episode of Embedded Insiders, Editor-in-Chief Ken Briodagh sits down with Ansgar Hein, Chairman of the Board at SGET e.V., to discuss the new Open Harmonized FPGA Module (oHFM) standard, the world’s first open standard specifically designed for FPGA and SoC-FPGA modules. 

Watch the segment here: https://youtu.be/mDyAJ8gfpg8

Next, contributing editor Rich Nass is joined by Thistle Technologies’ Founder and CEO, Window Snyder, to discuss the importance of incorporating security into your design. 

But first, Ken, Rich, and I are back from embedded world 2026 in Nuremberg, and we’re giving you a recap of all the top trends and technologies we saw. 


For more information, visit embeddedcomputing.com

Get every episode summarized

Each time Embedded Insiders publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

890 searchable segments. Every word is indexed and playable.

embedded world Recap, New oHFM Standard, & the Importance of Security

Embedded Insiders

0:00
38:32

Full transcript

Embedded Insidersembedded world Recap, New oHFM Standard, & the Importance of Security. Machine-transcribed; use the interactive transcript above to jump the player to any line.

a lot of the things that we know how to do to make platforms' systems more resilient. Had it made its way over to the devices space, and that's the core of what we're doing at Thistle Technologies. We're trying to make those capabilities easy to incorporate. On this episode of Embedded Insiders, Editor-in-Chief KenBriota, sits down with Ansgar Hine, Chairman of the Board at SKET, to discuss the new Open Harmonized FPGA Module Standard, the world's first open standard specifically designed for FPGA and SOC FPGA modules. Next, contributing Editor-rich NAS is joined by Thistle Technologies Founder and CEO, Windows Thrider, to discuss the importance of incorporating security into your design. But first, Rich Ken and I are back from Embedded World 2026 in Nuremberg,

and we're giving you a recap of all the trends and technologies we saw. Hello, everyone, and welcome back to the Embedded Insiders podcast. I'm Assistant Managing Editor, Tierra Oliver, joined with our Editor-in-Chief KenBriota and our contributing Editor-rich NAS. Hey, guys. You're looking at that, Tierra. I do. You know, I do too. I came back sick. Yeah, likewise. Absolutely, Germany. So, who did we catch you from? I assume it was Pat. It was probably Pat. Yeah, it's been the last couple of days. I've been like going to bed early and trying to sleep it off. I was sick on the flight, and I hacked all the way home over to Atlantic, and I felt really bad for the lady sitting next to me,

but what are you going to do? Yeah, that's rough. I couldn't sleep worth a damn on my flight, either. I had a hard time. So there was the low light. Let's talk about the high light. That's right, that's right. I thought it was a great Embedded World. For those of you who haven't caught the context, we've just returned from Embedded World in 2026 in Nuremberg to our various corners of the United States. Just to round out the four corners of the country, we've got to get somebody in here from like Washington or Oregon or something. But yeah, for those of you just catching up, we got back from Embedded World, and I think it was a great show, really like exemplary in my history at Embedded World. Great big crowd in terms of attendance. Lots of good energy. Lots of forward thinking stuff, instead of like reactionary,

I think we're over the hump of some of the COVID shortages and things like that. It was a big takeaway from it. I think people are looking forward. What about you guys? Did you feel the same way? Although first, the bar for me is really high for Embedded World. And it was a great show, but if it wasn't, it would have been a disappointment. Because I just have this standard for Embedded World, that's the best week of the year. And it lived up to that this year. Yeah, Tear, it was your first time. What do you think? It was, and I've sat on the podcast with you guys and listened to you recap this event a few times, and I thought it was great. I spoke to so many different people and learned so many things and just getting to learn firsthand in person and shake so many hands and have great meaningful conversations with people. Definitely, I think makes a difference from being back at home and just reading and talking to people via email

or whatever it may be, but it was great. So my question for you, Tiara, you've heard about the show and read about it, written about it and all that stuff for a whole bunch of years. How did it feel actually being there? Was it what you thought it was going to be? Was it different? It was as far as the fast pace and the crowd and everything, but I think it was still very, like I said, it was still very slow in the sense of when I sat down with people and had conversations. I didn't feel like the rush of like, okay, time to move on to the next meeting for most of them. It was very like, just very insightful being able to sit down and hear people speak in person. So I think it definitely lived up to my expectation and more. And did you feel like you were part of the, I was gonna say family, I'll say community, you know? Yeah, I think it's just awesome. There's a buzz there, I say this whole time and if you don't actually go, you don't get it.

There's a buzz there like no other event that I attend. Yeah, I think so, it's one of those events that turns you as a journalist and not an engineer. I sort of always have found that there's like a tent pole event that after you've gone to it, you start talking about the industry in the first person instead of the second person to yourself. I love that analogy. You start saying we, when you talk about embedded rather than you or they or whatever. And embedded world this year, absolutely had that vibe, I think. I'm gonna use that, I like that a lot. That's really good. Well, you know, one does one's best, Rich. We did some new stuff this year. It was very exciting. Probably my favorite thing that we were doing was the podcasting. We did, we had a podcast booth in our booth on the show floor. So lots of cool activity and buzz going on around it.

Between Rich and I, what did we do? Like 16 or 20 different interviews? Something like that. But it was so nice to have the podcast booth in our booth and have people come to us, what did that make life easier? Oh, sure. Not that I don't mind going around to people's booths, but by the time you find that booth, you find the people, you scramble to get that all the people in place. Now you're looking at your watch to see if you have another meeting to go to. This was such a relaxed atmosphere and the conversations were great. And it didn't help to have two hours in the middle of the day where you could sit down. I didn't say that. I did, I'll say it. I thought it was great. And looking back as they're almost all of them are live already on YouTube. So you can go and watch those, but those segments will be coming out here on embedded insiders over the next couple of weeks. I think you guys are gonna really enjoy the quality of the discussions. I mean, I really thought they were some of them were really great.

And Tierra was doing something new or new-ish for us. This is the first sort of broad spectrum out there recording YouTube shorts and short snippet videos. How did that go, Tierra? It was good. It was much easier than I expected. It was gonna be going into it, but. We're gonna tell the people that. No, it was great. I feel like we got pretty much all of our recordings and a few, in a few tries. But no, everyone was pretty confident, ready, and I think it went pretty smoothly. Awesome. I mean, we had, between the three of us, we had at least what 100 meetings or something between the three of us. It was more than that because I had 50 alone, and I assume you have 50 by yourself. Yeah, probably true. So Tierra, you must have had about the same. So we're not gonna go around here calling out

who was the best and everything, but I tell you, I had some great conversations with some of the industry association folks. Eclipse Foundation and RISC-5 stand right out to my mind. Really cool ecosystem conversations. Anything that you guys wanted to call out that you thought was pretty exciting and fun? I mean, I'll say in general, I met with a lot of like more well-known companies and then a lot of smaller ones, and I do find that my conversations with some of the smaller ones were a bit more meaningful than the bigger companies. No shade to the bigger companies. They did well and we had a great conversation, but I think some of the more small and more upcoming companies just surprised me the most, and they were all just so knowledgeable and confident, and some of them I'm very much looking forward to having on the podcast, so stay tuned for that in the future, for sure.

So I'll go now. The thing that struck me and this isn't to say they're really good or they're really bad, but what was really surprising to me was the push that was made by Qualcomm to get into embedded. I attended their partner day on Monday the day before the show and they have their Dragon Wing architecture, and they really are trying to get into embedded, and I listened to all them talk and they brought in their partners who you knew were gonna say good things about them, and that was all expected. However, when I got to the show the next day, many of the people on the show floor were also touting the things they're doing with Qualcomm. I wonder if this is one of those like we've seen others, and boy I hesitate to name names, but there's been other CPU guys who've been in embedded, out of embedded, in embedded, out of embedded, because they just can't figure it out. And I hope that's not the case with Qualcomm

because they have so much to offer, and the other thing related to that, which when they acquired Arduino, I never really understood why, and now I do. It makes a whole lot of sense, and it starts with the fact that there's Qualcomm Silicon on the Arduino board now. Right, but that's a foot in the door for embedded. It's pretty cool, I have to say I'm impressed by what they did at the show, and I don't know if it was supposed to be coming out party for them or not, but it certainly felt like it. I agree, I had a bunch of people that I talk to, talk about Qualcomm and a partnership there, and I think it's really exciting, you know, when Qualcomm, and Qualcomm doesn't do things by halfway measures historically, you know? In truth, when they entered the mobile market, they took it over, and like, you're hard pressed to find an Android phone

that isn't using a Snapdragon these days, you know? And I think that in a market like embedded, that is, to my estimation, rapidly be horizontalizing and becoming ubiquitous, integrating IoT and sensors in a huge way, integrating obviously AI in a huge way, and sort of turning that all into one embedded layer, in my opinion, allegedly. I think Qualcomm has a lot of incentive to stick around and do what they do best, which is make really powerful, really lightweight chips that are going, that are going to make some of the other silicon and chip manufacturers very, very nervous, because, well, honestly, I think they all better look out.

This is, if Qualcomm does it in a big way, I think there's a lot to be said, and that Arduino move in the summer, I was also very surprised to hear about it when it happened, because it happened fast, like it was very under wraps. I only got a heads up about it maybe 24 hours before the actual announcement, and it was, you know, it happened fast, and then we didn't hear a lot about it after, but you're right, that's groundwork. That's a foot in the door, and it seemed to me it embedded that that's the big story that hasn't been getting a lot of attention yet. They also had Fabio, who's the founder of Arduino's one of the speakers, and he was really entertaining. I'd never heard him in a keynote like that before. He's not among the podcast speakers. He's a really good speaker. I heard him these couple of years ago. We've had him on the embedded executive podcast a couple of years ago, and he was good.

Yeah, he's great. How was, Tierra, I know you got a chance to go to one of the keynotes. How was that? It was the, was it microchip? Yes, it was microchip, yeah. It was about distributed AI systems, and their whole analogy for that keynote was the octopus, which I thought was really interesting. It was just talking about power management as a differentiator for AI, and powering devices with more battery life, but without making significant hardware changes, and solving the power challenge at the edge. And of course, AI, just being another tool in the toolbox and how AI nodes are that tool. There's a lot of jumping around and good points that were made, and I'll definitely have a write-up about that posted up soon too. Absolutely. Yeah, I wanted to attend that one.

I didn't, I didn't have the time, but I would have liked to heard that. I heard the preview. Well, luckily you'll be able to read Tierra's article very soon to get the insights. I heard a ton about the memory shortage. Everybody's freaking out about that now. And an interesting take that you can hear on one of the podcast interviews that we recorded was that a lot of that fear is coming from the data center people sucking up all the memory and that there won't be any left for the embedded people. Pretty much all of it. Yeah. And I do have a podcast on that topic scheduled to dive a little deeper, but from what I understand, it's all related to the data center, and then willing to pay the top dollar for the memory. Yeah. While it seems like the industry as whole is much more interested in the edge, it's an interesting pull me, push me pull me situation happening there. And I think that the memory people

are going to have to ramp up to meet the need, and that's going to be a big boom for the memory and storage companies. Yeah, big boom there for them. And then the next one to come, that's going to have to be playing catch up, and they're going to have to get ready soon or the connectivity folks, because there's a lot of bandwidth that's going to be needed at the edge that isn't there now, and it's going to have to be a lot more resilient to RF interference than it is now. And I think that's going to be the next big thing is going to be all the connectivity. But we'll see. Good stuff. Maybe embedded world North America will give us some of these answers. We'll certainly have some answers by then. We'll know a little more about Clawcom. Yeah. We'll know a little more about what's going on with memory, and I don't know about the connectivity part though.

That might be a lot. On the road, I think, I think that'll be, nobody's going to worry about that yet until they've got all the volatile memory that they can get their hands on. Yeah. Yeah, but embedded world North America is coming. That's in September this year. Had to make room for the World Cup. Also in September, electronica, I think is in September. That's in November. Oh, no, that's in November. That's right. Yeah. Yeah. Yeah. Do you know that yours truly is the liaison to the embedded industry for embedded world North America? Oh, yes. I did know that. But now it's a little tidal. Now our listeners know it's good that they've got a liaison to the embedded industry. Otherwise, the embedded industry might not realize that it moved to September. So there you go. You call for papers is still out for that, right?

Or is that closed? No, it's still open for another three weeks or so. All right. So that's your deadline, folks. Get those in as soon as you can. Agreed. All right. Well, I think we've blathered on long enough. Tierra, you want to wrap us up here. Give us some structure. Yeah. I mean, I think we just have a lot of information for everyone to stay tuned about. Keep an eye on our site and check out those podcast recordings from Embedded World. And just keep an eye out on our site and on our YouTube to see what we've got tuned for Embedded World North America. Now if here's Ken and Ansgar Hein, Chairman of the Board at ESKET. Hello, friends, engineers and developers. Welcome to another segment of Embedded Insiders podcast. I'm Ken Brio to Editor-in-Chief of Embedded Computing Design and your host for this segment. Very excited to have you all listening. Thank you so much. I am delighted to be here with Ansgar Hein of ESKET.

And Ansgar is going to fill us in on some news that you absolutely need to know about. This is, there's a new OHFM standard. Ansgar, welcome to the program. Hey, Ken. Thank you for having me. So the pleasure is mine. It's great to finally get here to talk to you and to chat. My first question is an easy one. Tell us about the new standard. What is it? OK, so basically it's about FPGA. We are known for other standards that are very modular and open at ESKET. So for example, SMARC or OSM. And we thought about FPGA for a while and thought why not standardize modular FPGA components? So everybody told us, ah, that will be difficult. It's a whole different story than comes. And then we went for it. So we've got a lot of FPGA expertise in the group.

And so we created the first open harmonized FPGA module standard. So that is what OHFM stands for open harmonized FPGA module. And it comes into flavors, basically. So we've got it solverable and we've got to connect the base. So we've put all of our knowledge that we have inside of ESKET of solverable modules like we had with OSM and SMARC and can just have them connect their base modules into one big module standard, so to say. So we have a pretty big broad base of engineering disciplines and stuff in our listenership. Who's going to be most interested in it? Who's going to absolutely need to go out and figure this out? I mean, a lot of folks are working with FPGAs now, as you know, automotive everywhere, you know, there. Who's going to be looking for this in particular? I think it'll be engineers who are already into comms.

Also, those who are using FPGAs, there are several FPGA modules out there. That's for sure. But they like one thing, which is exchangeability. So you just have to stick with one vendor and then you have a vendor lock in. So if you're looking for a second source, then it'll probably be something you'll be searching for. So it could be also project managers, so to say, who are looking for something as a second source. So yeah, that makes sense. The so we've got embedded world coming up. I know that the SK is going to be involved there. Are we going to be able to see any sort of use cases or proof of concepts or anything in embedded world? So we don't have our own booth there because all of our members are there, but their own booth. And usually you don't get that personal at the embedded

world to cover our booth as well. But our members will be presenting OHFM. I know that at least IWave will be showcasing the first OHFM connector-based module there. And yeah, so I know there will be some of the members showcasing something, probably examples first, but the standards are the same. I know, that's awesome. That's really, really cool. Folks out there listening, if you're working in FPGA now or you've been thinking about playing around with it, adopting maybe this seems like the perfect opportunity. So make sure you're checking out the SKAT membership at embedded world because I know a bunch you'll be there or check it out on the internet, speaking with Jantzkar. Where can folks go to learn more about the new OHFM standard? Yes, on our website, actually. So it's all covered on SGET.org.

The standard documents are available to just to go through in your email address, except terms and conditions and download it for free. And you're ready to use it. So unless you want to commercialize it and make a module out of it, then you got to become a member, which is also very easy and straightforward. You can sign up online. So I think it's 900 for a start-up package. That's not too much. Incredible. And I encourage folks out there, go ahead and become a member. That's nothing. Then you've got all the access that you need to do. In the meantime, thank you so much, Jantzkar, for taking the time to talk us through the standard, introduce it to the listener ship. I really appreciate it. Thank you, Cam. And to you folks out there listening, remember, if you haven't subscribed yet, if you've just been had this podcast shared with you, make sure you give your friend who shared it with you a hug and subscribe. Because you don't want to miss any of our episodes of embedded insiders. And if you're watching us on YouTube, you'll notice that we do these on video now.

So subscribe to us here on YouTube, if that's where you are, if you're not there, get over there. And click the notification bell, do all the things, and you'll find the link to the new standard down in the show notes. So thank you all so much for listening. Thank you so much, Jantzkar, and ask it for helping us out. Thank you, Cam. Have a great day, folks. Now, here's Rich and Windows Knighter, founder and CEO of This Little Technologies. Here's an afternoon. My name's Rich Ness. I am with embedded computing design. My guest this week is Windows Knighter, and she is the founder and CEO of This Little Technologies. How you doing, Wendell? I'm doing all right. Thanks for having me. My pleasure. So in full disclosure, we work together on a panel not too long ago and an event for Infinian. And I was rather enthalled and thralled by what you had, not so much what you had to say, but how you set it in your passion for security

really comes across like you really care about this stuff. So I thought I wanted to share all that stuff with our audience. So before we get into the security part and how you do it and why you do it, just a little bit of background. Tell us who This Little is and what have you been doing for the last, I don't want to date you, but a number of years. All right, so This Little Technologies builds software, tools and libraries and backend services that allow embedded developers to incorporate sophisticated security capabilities into their product projects really quickly and easily. And you yourself, what's your history? Sure, prior to starting this company, I was the chief security officer or the CISO at a number of companies including Square, Fastly, Mozilla. I was the chief software security officer at Intel. I owned all the security and privacy features for iOS and OS 10 at Apple for almost six years. I own the security sign off for the Windows operating system

while I was at Microsoft for a number of years. I was a security software engineer, a security researcher, a security consultant. I've been in the space for over 30 years and have kind of seen a lot. And in my role at Intel, I got to see that despite all this work that we had done in the industry for general-purpose operating systems, a lot of the things that we know how to do to make platforms, systems more resilient, hadn't made its way over to the devices space. And that's the core of what we're doing at This Little Technologies we're trying to make those capabilities easy to incorporate. Okay, I want to come back to that because easy is just something that's not easy. But you started this all when? About five years ago. Okay, all right. So so many people do security from the MCU vendors themselves on all the way down. Some people say you need hardware, some people say software, some people say you need both. What are you doing that's different from what everybody else is doing and why should somebody trust you?

So you're absolutely right in terms of like, you need all kinds of things in order to build resilience in a system. But what you really need depends on your security requirements and try not to understand what your project action means, what's justified. For devices is really different than for software because devices might live out in the world for five, 10, 15, 30 years if we're talking about an MRI or a car. So it really depends on what you're building. So that's the first step. And then the second aspect of this is that the threats continuously change and how we use it also changes. So that's another thing. So trying to build something that is going to be resilient for the lifetime of the device is incredibly challenging. And that's why we want to make these low-level capabilities that allow you to establish a hardware-rooted trust easier because if you, for example, let's take update, right? If you can't update your device, then you're never going to get to a place where you can address a security issue and maintain security resilience, right? And you might have an update mechanism, but do you have an update mechanism that you're confident enough to ship a fix for, right?

Because if that device doesn't come back up, then it's potentially lost forever, right? If we're talking about a 2% failure rate, a 3% failure rate, and we know for a lot of devices, the failure rate can actually be way higher than that when we're talking about update. Because we're updating really low-level components, we're updating firmware, we're updating drivers. The set of things that can go wrong is significant. So having an update mechanism that is reliable enough that you're willing to push out that update to address that security issue, that is a foundational security feature. And a lot of folks don't think about update as a security feature. They think of a fix being the security component update is just plumbing. But that plumbing is actually critical to being able to deploy these updates. So update is one of the first to these. But establishing that hardware root at rest, being able to tie your crypto operations back into this hardware capability or to a key that's protected by hardware is incredibly important. If you want to, let's say, have confidence that the update came from someplace that you're able to recognize, that you want the device to be able to recognize the device came from someplace. And when the code is executing on the system, you don't want it to execute if it's not the code

that that's the device recognizes. So we start getting into things like security boot and establishing a secure execution chain and building what we call the security supply chain, right? Making sure that you, first of all, know where it's coming from at that only the things that are supposed to execute on the device, execute on the device. And all of the security plumbing is incredibly difficult to do. And for folks that build, let's say, security for devices, that encompasses all kinds of stuff. They might be building authentication, they might be building the equivalent of an IDS looking for, let's say anomalies happening on the system that might be somebody trying to do something malicious on the device. But establishing these fundamental resilience capabilities allows you to do everything else. Nothing else matters if you don't have that resilience built into your device. Excellent. Most of the experts who I speak to say that it's impossible to build a system that's 100% secure. That you just want to make it hard enough that the bad guys will just go elsewhere. Do you believe that as well? You can't make a system 100% secure.

That is absolutely true. But you can make it secure enough for your requirements, right? So if you are, let's say, trying to meet your CRA regulatory requirements, that might be the requirements for your system. If you're trying to meet your customers' expectations, that might be the requirement for your system. If you're trying to build a system that is going to be resilient enough that you can deploy it and believe that it will be operable in the field for 20 years, right? You're going to have different security requirements. If you're trying to thwart nation-state actors, that's a whole other thing. If you're trying to deploy a device out there that is going to have your AI model executing at the edge on a device that is in an environment that you don't control, and you want to protect that IP, you've got a different set of requirements. So you can do work that is appropriate to achieving the security requirements you have for your system. And of course, nothing's ever 100% secure. But you can get to a place where you have, let's say, a sufficient degree of confidence that your product will be able to do the work that it's

deployed in the world to do safely. Do we kick some of this back to the user? I mean, it's obvious that things need to be updated once they're out in the field. Does that on us go back onto the user to make sure that devices are up to date or is that on the vendor to make sure? So product teams love to put this on the users. And I think as an industry we're moving away from this because it's not really fair. But I'm sure you remember guidance like, oh, be sure you know where this link goes before you click on it or things like that, right? For an email, make sure you trust the sender before you blah, blah, blah. No, you should be able to evaluate whether or not this is coming from where you think it is. It should be hard for someone to spoof an email from wherever a link that you click on should be safe, right? It's not the user's responsibility to evaluate whether or not the link is safe no matter what these IT teams tell their folks. It should be that the OS is smart enough to evaluate

whether this is going to do something malicious to the system. And all that's incredibly difficult. I know we talked a little bit about making things easy, but easy is hard, easy is incredibly hard. It will be really hard to create a system that is so resilient that the user could accidentally install something malicious on their system and the system goes, ah, that's a terrible idea. We're not going to let that install. We're going to flag it for you. We're going to let the IT team know. We're going to prevent that from executing. Instead of like the model we had about 10 years ago, which is that you click on something and the next thing you know, not only is your system compromised but the entire infrastructure for your organization that's compromised oops, right? Like, it easy is hard, right? But you can get to a place where you've got a degree of security resilience where instead of let's say the honest being on the user to keep their infrastructure up to date so that the attack service that's exposed on this network isn't as accessible to the attackers. Like, yeah, okay, it doesn't matter how you deploy it. That's fair. But you know, staying up to date, like are you actually shipping an update? Is the update, let's say reliable enough that the user has confidence

that they're not going to have downtime with the system? Like if we're talking about industrial manufacturing, that is like real time on the line, that the system is down and that's money, right? Every time I put myself system for a large retail environment, that's the revenue that's just lost, right? If we're talking about a car in the field that has a problem with their update that to come back to the dealership when we've seen that happen over the last year we've had updates that ship up that it caused problems that require the car to come back to the dealership for a fix. If it's a phone, right? And we've got a hundred million devices out there that's potentially with a 1% failure rate. You know, a million devices that have to come back to the most store or to a provider because very often the user can't get that up and running themselves, like it's not, it's not a simple thing, it's not easy, easy as hard. But easy still, it's required. We need to make security easy so that the onus is non-user. Even if we're talking about consumer products, even if we're talking about devices that are deployed into environments that have an IT team that is available to fix these things. If we're talking about devices, they're out in the world doing a job, right?

It might be a consumer device in which case there's, you know, maybe a smart home network that they can rely on for some medications, but for the most part, we just have to build systems that expect the worst, that operate in spite of all the things that can go around and that are able to be reset to a known good state so that you can build that confidence again back from hardware that the things that are executing on the system are the things you expect as a user or as a device manufacturer and that you can manage those devices so that they are able to recognize that they're in a known good state. Very good. See, you mentioned earlier about how embedded devices are often deployed five years, 10 years, 20 years is not that uncommon. So what do we do about some of these devices that have already been out there for 20 years and we know aren't built to the levels of security that we need? Do we just keep our fingers crossed

and hope for the best? Whereas is there some solution? So one of my favorite painful moments was I think it was last summer when the FBI released a report about a bot network that was operating through home routers and cable modems and, you know, hundreds of millions of devices were compromised and they're actively being used to exploit other systems as part of this bot network. And the only guidance they can give to folks if you own one of these routers is to go buy another one, which is infuriating, right? That's infuriating. But it's true that for these devices that might have deployments in hundreds of millions that the option to update, even if they are able to ship an update for it, which maybe they are, maybe they aren't. But if they're able to ship an update for it, but they've got like a 1% failure rate, which is low, it's probably closer, it's probably a double digits, but let's just say it's a 1% failure rate. That's a million devices that are calling in and say to their internet service provider saying, Adam, I hit net is down. And then the answer for this folks is to be like, don't worry, download this firmware update, use a USB cable, plug it into your computer, plug that into the router and do a firmware update

or a USB to blah, blah, blah. How did they even download the firmware update in the first place, right? Is a completely unreasonable prospect to try and get those devices back up today if they fail. So the FBI is left with being forced to give guidance like go buy another one. That is terrible. And it's absolutely terrible. That's not what we want. We do have to figure something out for brownfield devices in there, folks out there who are doing things like China and deploy them in air gap networks or put things in front of them so that they are less likely to receive input that's unvalidated from malicious sources. There are some things that we can do. And for devices that actually have a shell that there are some options that we'll be working on later for adding security kind of after the fact for the devices that are already in deployment. But we're all builders, right? We're building stuff today, right? So we can avoid making the same mistakes in the future that we've made in the past and move forward with a much more resilient security infrastructure for which to build on. Because we know that threats are going to constantly change

that they're going to evolve and so far they've only gotten worse. So far they've only gotten worse in terms of like the the amount of folks that are invested in compromising these devices, these systems. It's these are high value systems that are connected to real world physical systems that have real world physical impact. And whether that's human safety or that's national infrastructure, there's a critical reason that we need to do this work now. So we don't end up in the state 20 years from now still going, oh no, what do we do about all these brown, this past 20 years of brown field devices? We have to do the work. Awesome, this is a very interesting and not an issue that's going on anytime soon. I fear it'll get worse before it gets better. Well, some part of it is getting better. It's getting easier to incorporate the capabilities and that's what I've been working on. I'm trying to just make it easier to get these capabilities in place because it's hard. So we're trying to make it easier. Very good. Well, thank you, Window. I do appreciate you taking the time to educate the audience. Absolutely, thanks for having me.

That was Window Snyder. She is the founder and CEO of Digital Technologies and I am rich now with embedded computing design. Thanks for listening to this edition of Embedded Insiders. For more daily news, videos, and podcasts, visit our website at embeddedcomputing.com.

More episodes

More from Embedded Insiders

View all episodes →