Big acknowledgment to @ThreatLocker for sponsoring my travel to Black Hat USA 2026 and besides for sponsoring this video. To commencement your free proceedings pinch ThreatLocker please usage the pursuing link: https://www.threatlocker.com/davidbombal
You tin constitute unafraid C code, travel accepted champion practices and still extremity up pinch a susceptible binary. The logic is simple: the CPU does not tally your root code. It runs immoderate the compiler produces.
David sits down pinch information interrogator Chris Domas astatine Black Hat to analyse really ineligible compiler optimizations tin region information protections, delete memory-clearing operations and present time-of-check to time-of-use vulnerabilities into codification that appeared secure.
Chris explains the C absurd machine, why compilers are allowed to toggle shape codification truthful dramatically and really registry pressure, building layout and moreover information size tin impact whether a binary is vulnerable. In 1 striking example, 17 aliases 33 bytes tin beryllium safe while adjacent sizes nutrient susceptible code. They besides talk whether Rust solves the problem, why switching betwixt GCC and Clang is not the reply and really AI helped analyse 500 cardinal lines of open-source codification to place 300 perchance vulnerable patterns.
Most importantly, Chris explains what developers tin do now, including enabling compiler warnings, utilizing sanitizers, analysing optimized builds and testing the nonstop binary that will beryllium shipped.
// Christopher Domas’ SOCIAL //
LinkedIn: / christopher-domas
GitHub: https://github.com/xoreaxeaxeax
X: https://x.com/xoreaxeaxeax
// David’s Social //
================
Coect pinch me:
================
Discord: http://discord.davidbombal.com
X: https://www.x.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube Main https://www.youtube.com/davidbombal
YouTube Tech: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A
YouTube Clips: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Emerging Technologies: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Shorts: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg
Apple Podcast: https://davidbombal.wiki/applepodcast
Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: / davidbombal
================
Support me:
================
Or, bargain my CCNA people and support me:
DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna
Udemy CCNA Course: https://bit.ly/ccnafor10dollars
GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested successful sponsoring my videos? Reach retired to my squad here: [email protected]
// MENU //
0:00 – Coming Up
0:48 – Intro
02:05 – Different Ways of Exploiting CPU’s
04:10 – The C Specifications
06:17 – The Compiler Deleting Nemsec
08:40 – Do we request to usage a caller Compiler ?
10:09 – Compiler Inventing Vulnerabilities
12:13 – Don’t Give up Writing Secure Code
12:44 – Sponsored Section
14:25 – Any Easy Options To Create A New Compiler ?
15:09 – Chris’s Presentation astatine Black Hat
20:00 – Weird Situations pinch Size of Data
21:22 – What Can Developers Do ?
23:32 – Who Can Leverage this Vulnerability ?
25:02 – Could AI Make it Easy For Attackers To Leverage This?
28:27 – Recommendations For Developers
29:48 – Advice To Be Like Chris
30:36 – Conclusion & Outro
Please statement that links listed whitethorn beryllium connection links and supply maine pinch a mini percentage/kickback should you usage them to acquisition immoderate of the items listed aliases recommended. Thank you for supporting maine and this channel!
Disclaimer: This video is for acquisition purposes only.
#bhusa2026 #securecoding #compiler
English (US) ·
Indonesian (ID) ·