#602: How Compilers Turn Secure C Code Into Vulnerable Binaries

#602: How Compilers Turn Secure C Code Into Vulnerable Binaries

Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces. David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure. Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns. Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped. // Christopher Domas’ SOCIAL // LinkedIn: / christopher-domas GitHub: https://github.com/xoreaxeaxeax X: https://x.com/xoreaxeaxeax // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:48 - Intro 02:05 - Different Ways of Exploiting CPU’s 04:10 - The C Specifications 06:17 - The Compiler Deleting Nemsec 08:40 - Do we need to use a new Compiler ? 10:09 - Compiler Inventing Vulnerabilities 12:13 - Don't Give up Writing Secure Code 12:44 - Sponsored Section 14:25 - Any Easy Options To Create A New Compiler ? 15:09 - Chris’s Presentation at Black Hat 20:00 - Weird Situations with Size of Data 21:22 - What Can Developers Do ? 23:32 - Who Can Leverage this Vulnerability ? 25:02 - Could AI Make it Easy For Attackers To Leverage This? 28:27 - Recommendations For Developers 29:48 - Advice To Be Like Chris 30:36 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #bhusa2026 #securecoding #compiler

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(500)

#608: Before You Deploy AI Agents, Understand These Attacks

#608: Before You Deploy AI Agents, Understand These Attacks

Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription How do you hack an AI system? And what happens...

19 Sep 52min

#607: How Hackers Steal Your Accounts Even With 2FA Enabled

#607: How Hackers Steal Your Accounts Even With 2FA Enabled

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.thre...

19 Sep 31min

#606: Is Cybersecurity Still Worth Learning in 2026?

#606: Is Cybersecurity Still Worth Learning in 2026?

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker, please use the following link: https://www.thr...

19 Sep 31min

#605: Flock Cameras: What They Can Reveal About Your Life

#605: Flock Cameras: What They Can Reveal About Your Life

Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off. Your license plate could reveal more than you t...

12 Sep 22min

#604: How He Infiltrated LockBit and Helped Get Them Indicted

#604: How He Infiltrated LockBit and Helped Get Them Indicted

Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount. John DiMaggio created fake identities...

12 Sep 24min

#603: How Age Verification Threatens Your Online Privacy

#603: How Age Verification Threatens Your Online Privacy

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.thre...

8 Sep 47min

#601: Google Researchers Hacked the Pixel Phone using Audio Messages

#601: Google Researchers Hacked the Pixel Phone using Audio Messages

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.thre...

8 Sep 39min

Populært innen Teknologi

tomprat-med-gunnar-tjomlid
teknisk-sett
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
energi-og-klima
lydartikler-fra-aftenposten
nasjonal-sikkerhetsmyndighet-nsm
hans-petter-og-co
elektropodden
rss-ki-praten
shifter
rss-alt-som-gar-pa-strom
rss-ai-forklart
smart-forklart
teknologi-og-mennesker
fornybaren
rss-snakk-om-sikkerhet
rss-alt-vi-kan
pedagogisk-intelligens
rss-heis
rss-ki-til-kaffen