Loading…
May 21 - 22 | Minneapolis, Minnesota
View More Details & Registration
Note: The schedule is subject to change.

The Sched app lets you build your schedule, but it is not a substitute for event registration. You must be registered for Linux Security Summit North America 2026 to participate in the sessions. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.


Thursday May 21, 2026 9:05am - 9:35am CDT
The Lockdown LSM is intended to ensure the integrity of all code in kernel space. Hibernation is a technology that allows the entire contents of RAM to be stored to disk and then later restored. What stops an attacker modifying the contents of the hibernation image, or providing their own hibernation image that contains malicious code, violating the design goals of Lockdown? The answer at the moment is "Lockdown disables hibernation", and everyone agrees that this is a bad answer. Let's fix that.

This presentation will describe the design and implementation of a patchset that allows hibernation images to be secured using hardware-backed keys, tied to system state in a way that prevents them being extracted and used to sign a malicious image. It will cover some of the corner cases and describe future work that would enable additional behavioural guarantees that are not part of the initial implementation. We will then discuss whether this is the right way of solving the problem, what alternatives there might be, and whether any of this is worth t at all.
Speakers
avatar for Matthew Garrett

Matthew Garrett

Principal Security Developer, NVIDIA
Matthew is an abyss domain expert, and has a long list of recommendations of which portions of the abyss are best to gaze into. He has worked on security throughout most of the stack, from hardware to firmware to kernels to desktop applications and pretty much everything else.
Thursday May 21, 2026 9:05am - 9:35am CDT
101A+B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link