Embedded
Chris and Elecia talk about pushing out of their comfort zone, networking advice, adding STARs and action verbs to resumes, using rust, thermo forming plastics, soldering together audio gear, and winning awards. If you are looking for an update to your resume or are interviewing for a new job and you haven’t heard of the STAR method (Situation, Task, Action, Result), it is a good way to formulate what you’ve done in a way that helps people see your impact. The that includes how to take your current, boring “did the task” resume bullet point and move it into STAR format and then...
info_outlineEmbedded
Dr. Victoria Serrano spoke with us about STEM outreach, fostering curiosity, and inspiring students with engineering education. Victoria is a professor at the Technological University of Panama (her faculty page: ). Her youtube channel is which talks about circuits, electronics, and robotics. The channel goes along with her website which shows the types of courses and outreach she does with Arduino UNOs and other low cost equipment. Victoria is also a Fulbright Scholar, an IEEE STEM Champion 2023, and Honorable Mention IEEE Rising Stars Conference 2024. She also received the IEEE EAB...
info_outlineEmbedded
Dr. Tom Williams spoke with us about robots, ethics, teaching, and books. Then we talked about mines, umpires, water, and more books. Tom is the author of (free at MIT Press: !). As part of the discussion, we talked about some other books and media: Nonfiction: by Ayanna Howard (Embedded episodes and ) by Philip Koopman (related Embedded episode ) by Kate Crawford Waki Kamino’s research on robot umpires: (or see the summary in the Cornell Chronicle: ) Fiction: by Becky Chalmers by Martha Wells (Embedded episode ) by Nnedi Okorafor was...
info_outlineEmbedded
Nathan Jones spoke with us about hardware security, motivation, conference talks, and writing. Nathan wrote an in-depth series of posts about the benefits of superloops vs RTOS: , , , and . He also wrote about and which discusses the . See his and . And Nathan’s excellent Github repo. Nathan recommends by Jasper van Woudenberg and Colin O'Flynn. It is an excellent resource on embedded security. We spoke with Jasper about the book in and with Colin about the Chip Whisperer in . The has specific features that are required to be implemented by all devices that want the safety CE label....
info_outlineEmbedded
Chris and Elecia chat about Leapfrog toys, things they like, large company politics, awards, and open source governance. The with LilyPad toy which is suspiciously similar to the tablet. Which is different from the which had cartridges and capacitive touch (capacitive touch was used on the as well… the ). Why does Elecia want an award? Who knows? But right now, she’s getting ready for a listener to nominate the show (Chris and Elecia) for IEEE’s . Probably. But we’ve got nominators and endorsers so that’s mostly sorted. She also signed Embedded up for the Women Podcasters...
info_outlineEmbedded
Sonia Grego speaks with us about a topic no one likes to talk about, but could be used to monitor personal dietary health and widespread disease outbreaks. Toilets! Sonia leads Duke University’s Smart Toilet Lab and the spin out Coprata which makes the Microbiome Activity Tracker. As discussed in the show, when developing a project far from where it will be deployed, there are many common issues. The chapter of Sonia’s recent book gives an excellent introduction to the unexpected environment far from the comfort of desks. The book is (free online!) , See , the as...
info_outlineEmbedded
Kenneth Finnegan entertained us with stories about accidentally contributing to the internet’s ability to network. Wondering how the internet works? All those terms about IPv4, IPv6, BGP, OSPF, CDN and other alphabet soup? Check out the YouTube videos by . Kenneth writes about his adventures on his blog, . Some of the posts related to this show are: We also mention FCIX aka or the You can also find Kenneth at where you will find more about half-dollars, nickels, and trains. If you also secretly long to run a locomotive, take a look at the program at WPRM. The title is...
info_outlineEmbedded
Chris and Elecia apologize, discuss uses and abuses of chatbots, reach out to an uncertain manager, try to help someone out of their professor’s draconian rules, and extol the joys of reading. is in Oakland, CA, US. It is wonderful! Some suggestions for UncertainManager: Hang in there! You are probably doing better than you think. Audio books are great! In the US, many libraries have digital libraries with extensive audio collections. There are several apps with different catalogs for the same library Libby, Kanopy, Hoopla, and Palace (check out the California shelf at...
info_outlineEmbedded
Mark Omo and James Rowley spoke with us about safecracking, security, and the ethics of doing a bad job. Mark and James gave an excellent talk on the development of their safecracking tools at . It included a section of interaction involving the lock maker’s lawyers bullying them and how the Electronic Frontier Foundation () has a to support security research. As mentioned in the show, the US Cyber Trust Mark baseline has a very straightforward checklist; is the overall standard, is the technical checklist, is the non-technical (process/maintenance) checklist. Roughly the process is...
info_outlineEmbedded
James Cameron spoke with us about programming for and operating a large telescope. The show is a blend of astronomy, engineering on the fly, and weird lady bug habitats. The (AAT) is part of the Australian National University’s in Coonabarabran, New South Wales, Australia. The AAT has an where you can check in on a very dark sky. James was on where we talked about the Forth programming language and his experiences with One Laptop Per Child. Unrelated to the AAT, Chris took this image of the Andromeda Galaxy (M31) from his over 9 hours (multiple days), stacking...
info_outlineNick Kartsioukas joined us to talk about security in embedded systems.
Common Vulnerabilities and Exposures (CVE) is the primary database to check your software libraries, tools, and OSs: cve.org.
Open Worldwide Application Security Project (OWASP, owasp.org) has information on how to improve security in all kinds of applications, including embedded application security. There are also cheatsheets, Nick particularly recommends Software Supply Chain Security - OWASP Cheat Sheet.
Wait, what is supply chain security? Nick suggested a nice article on github.com: it is about your code and tools including firmware update, a common weak point in embedded device security.
Want to try out some security work? There are capture the flag (CTF) challenges including the Microcorruption CTF (microcorruption.com) which is embedded security related. We also talked about the SANS Holiday Hack Challenge (also see Prior SANS Holiday Hack Challenges).

This episode is brought to you by RunSafe Security.
Working with C or C++ in your embedded projects? RunSafe Security helps you build safer, more resilient devices with build-time SBOM generation, vulnerability identification, and patented code hardening. Their Load-time Function Randomization stops the exploit of memory-based attacks, something we all know is much needed. Learn more at RunSafeSecurity.com/embeddedfm.
Some other sites that have good information embedded security:
-
This World Of Ours by James Mickens is an easy read about threat modelling
-
Cybersecurity and Infrastructure Security Agency (CISA) is at cisa.gov and, among other things, they describe SBOMs in great detail
-
National Institute of Standards and Technology (NIST) also provides guidance:
-
NIST SP800-213 IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements
-
There is a group of universities and organizations doing research into embedded security: National Science Foundation Center for Hardware and Embedded Systems Security and Trust (CHEST). Descriptive overview and the site is nsfchest.org
-
European Telecommunications Standards Institute (ETSI) - Consumer IoT Security
-
Camera Ubiquiti configuration issue (what not to do)
Finally, Nick mentioned Stop The Bleed which provides training on how you can control bleeding, a leading cause of death. They even have a podcast (and we know you like those). Elecia followed up with Community Emergency Response Teams (CERT). Call your local fire department and ask about training near you!
Transcript