IoT security for the engineers who have to ship the device.

Weekly engineering deep-dives, vulnerability teardowns, and CRA compliance guidance — written by a practicing embedded engineer, not a vendor.

Get the CRA Compliance Checklist →

Latest posts

Engineering April 14, 2026 · 12 min read

Secure Boot Isn't "Just Turn It On" — What Embedded Engineers Actually Miss

Secure boot is a chain of trust, not a checkbox. Most embedded teams implement the first link (ROM verifies the bootloader) and stop. Under the EU Cyber Resilience Act, a half-implemented secure boot won't just be a security problem — it'll be a compliance problem with a 24-hour reporting clock.

One post a week, plus the CRA checklist on signup.

No marketing.