APPLIED RESEARCH • SANTA CLARA, CALIFORNIA
Hardwear.io USA 2025: ten lessons shaping our hardware security practice
From May 27–31, 2025, our team attended Hardwear.io USA in Santa Clara to follow research showing how physical faults, firmware, protocols, and chains of trust combine into real risk. The experience reinforces Cybersecurity as a hands-on EAGLE BS specialty—from architecture through testing and remediation.

Hardware security neither ends at the circuit nor begins only in software. It lives at the boundaries: bootloader and operating system, device and cloud, protocol and implementation, laboratory and field. That integrated view defined Hardwear.io USA 2025.
The conference brought together researchers, manufacturers, and security practitioners to examine attacks and defenses for connected devices. For EAGLE BS, engaging with this work means converting current research into better architecture, risk assessment, and secure-engineering decisions for our clients.
CYBERSECURITY
Ten technical signals we are bringing into projects
- 01
Zephyr OS still requires defense in depth
Eric Evenchick explored vulnerabilities in Zephyr-based systems. A modern RTOS does not replace configuration review, isolation, secure updates, attack-surface analysis, and device-specific testing.
- 02
Skimmers demonstrate the value of hardware forensics
Aidan Quimby showed techniques for reverse-engineering card skimmers and recovering compromised data. The case highlights evidence preservation, component and firmware analysis, and the link between physical behavior and digital fraud.
- 03
Classic flaws remain relevant in modern IoT
Baptiste Moine's case study of a blind format-string vulnerability showed that well-known errors still reach current connected products. Dependency inventories, hardened builds, fuzzing, and code review remain essential.
- 04
Glitching moves the trust boundary
Cristofaro Mune presented privilege-escalation paths on Google Wifi Pro using glitching. Logical controls can fail when an attacker manipulates power, clock, or execution timing; secure boot and critical checks must account for physical attacks.
- 05
The head unit belongs to the automotive attack surface
Danilo Erazo examined vulnerabilities in automotive head units. Even user-experience components need segmentation, least privilege, and tightly controlled interfaces so they do not become pivot points.
- 06
Proprietary protocols do not guarantee security
James Chambers and Sultan Qasim Khan discussed weaknesses in the PowerG wireless protocol. Encryption, authentication, pairing, replay protection, and key management must withstand independent analysis rather than rely on obscurity.
- 07
Flash protection must withstand real extraction attempts
Mark Omo and James Rowley introduced STM32-TraceRip for extracting protected flash. Protection bits, debug locks, and read policies must be evaluated on silicon and against the product's actual threat model.
- 08
Post-quantum systems will still face implementation attacks
Markku-Juhani O. Saarinen examined attacks on post-quantum roots of trust. Changing algorithms is not enough: verification logic, timing, side channels, updates, and key protection remain system-security concerns.
- 09
Open silicon expands both transparency and responsibility
Olivier Thomas addressed integrated-circuit validation in open-source silicon projects. Auditability helps, but it requires equally mature verification, traceability, and supply-chain security.
- 10
Rowhammer remains an evolving risk class
Stefan Saroiu's retrospective covered progress and open challenges across six years of research. Point mitigations age; memory, controllers, and software must be assessed as a system throughout their lifecycle.
What this changes in practice
The research points to one shared conclusion: security must begin with the product. A mature assessment combines threat modeling, architecture review, firmware analysis, physical-interface testing, boot and update verification, protocol assessment, and observation under adverse conditions.
It also changes what counts as evidence. A protection named in a datasheet is only a starting point; teams must prove how it behaves in the final device, with real configuration, real dependencies, and an adversary able to interact with the hardware.
How EAGLE BS turns research into engineering
Our Cybersecurity work connects applied research to delivery: we identify assets and trust boundaries, prioritize risk by business impact, test technical hypotheses, and help design remediations that fit the product and its operating reality.
Hardwear.io expands the knowledge used in firmware, IoT, embedded-system, and connected-architecture assessments. The goal is not simply to follow trends, but to recognize failure classes earlier and build systems that remain defensible after release.


RELATED EXPERTISE
Cybersecurity for hardware, firmware, IoT, and embedded systemsSOURCES AND OFFICIAL CONTEXT
Hardwear.io USA 2025 — official event pageEAGLE BS
Does your connected product need a security assessment?
Talk to EAGLE BS about secure architecture, firmware, hardware, IoT, and risk-led testing.


