APPLIED RESEARCH • SANTA CLARA, CALIFORNIA

Hardwear.io USA 2025: ten lessons shaping our hardware security practice

From May 27–31, 2025, our team attended Hardwear.io USA in Santa Clara to follow research showing how physical faults, firmware, protocols, and chains of trust combine into real risk. The experience reinforces Cybersecurity as a hands-on EAGLE BS specialty—from architecture through testing and remediation.

9 minPublished July 21, 2026
EAGLE BS team at Hardwear.io USA 2025 in Santa Clara
EAGLE BS attended Hardwear.io USA 2025 in California.

Hardware security neither ends at the circuit nor begins only in software. It lives at the boundaries: bootloader and operating system, device and cloud, protocol and implementation, laboratory and field. That integrated view defined Hardwear.io USA 2025.

The conference brought together researchers, manufacturers, and security practitioners to examine attacks and defenses for connected devices. For EAGLE BS, engaging with this work means converting current research into better architecture, risk assessment, and secure-engineering decisions for our clients.

CYBERSECURITY

Ten technical signals we are bringing into projects

  1. 01

    Zephyr OS still requires defense in depth

    Eric Evenchick explored vulnerabilities in Zephyr-based systems. A modern RTOS does not replace configuration review, isolation, secure updates, attack-surface analysis, and device-specific testing.

  2. 02

    Skimmers demonstrate the value of hardware forensics

    Aidan Quimby showed techniques for reverse-engineering card skimmers and recovering compromised data. The case highlights evidence preservation, component and firmware analysis, and the link between physical behavior and digital fraud.

  3. 03

    Classic flaws remain relevant in modern IoT

    Baptiste Moine's case study of a blind format-string vulnerability showed that well-known errors still reach current connected products. Dependency inventories, hardened builds, fuzzing, and code review remain essential.

  4. 04

    Glitching moves the trust boundary

    Cristofaro Mune presented privilege-escalation paths on Google Wifi Pro using glitching. Logical controls can fail when an attacker manipulates power, clock, or execution timing; secure boot and critical checks must account for physical attacks.

  5. 05

    The head unit belongs to the automotive attack surface

    Danilo Erazo examined vulnerabilities in automotive head units. Even user-experience components need segmentation, least privilege, and tightly controlled interfaces so they do not become pivot points.

  6. 06

    Proprietary protocols do not guarantee security

    James Chambers and Sultan Qasim Khan discussed weaknesses in the PowerG wireless protocol. Encryption, authentication, pairing, replay protection, and key management must withstand independent analysis rather than rely on obscurity.

  7. 07

    Flash protection must withstand real extraction attempts

    Mark Omo and James Rowley introduced STM32-TraceRip for extracting protected flash. Protection bits, debug locks, and read policies must be evaluated on silicon and against the product's actual threat model.

  8. 08

    Post-quantum systems will still face implementation attacks

    Markku-Juhani O. Saarinen examined attacks on post-quantum roots of trust. Changing algorithms is not enough: verification logic, timing, side channels, updates, and key protection remain system-security concerns.

  9. 09

    Open silicon expands both transparency and responsibility

    Olivier Thomas addressed integrated-circuit validation in open-source silicon projects. Auditability helps, but it requires equally mature verification, traceability, and supply-chain security.

  10. 10

    Rowhammer remains an evolving risk class

    Stefan Saroiu's retrospective covered progress and open challenges across six years of research. Point mitigations age; memory, controllers, and software must be assessed as a system throughout their lifecycle.

What this changes in practice

The research points to one shared conclusion: security must begin with the product. A mature assessment combines threat modeling, architecture review, firmware analysis, physical-interface testing, boot and update verification, protocol assessment, and observation under adverse conditions.

It also changes what counts as evidence. A protection named in a datasheet is only a starting point; teams must prove how it behaves in the final device, with real configuration, real dependencies, and an adversary able to interact with the hardware.

How EAGLE BS turns research into engineering

Our Cybersecurity work connects applied research to delivery: we identify assets and trust boundaries, prioritize risk by business impact, test technical hypotheses, and help design remediations that fit the product and its operating reality.

Hardwear.io expands the knowledge used in firmware, IoT, embedded-system, and connected-architecture assessments. The goal is not simply to follow trends, but to recognize failure classes earlier and build systems that remain defensible after release.

RELATED EXPERTISE

Cybersecurity for hardware, firmware, IoT, and embedded systems

SOURCES AND OFFICIAL CONTEXT

Hardwear.io USA 2025 — official event page

EAGLE BS

Does your connected product need a security assessment?

Talk to EAGLE BS about secure architecture, firmware, hardware, IoT, and risk-led testing.

Talk to a specialist
WhatsApp