Skip to content

ejaaskel

Embedded Software Handyman

  • Current Page: Home
  • About Me
  • Yocto Hardening
  • Mailing List
  • Current Page: Home
  • About Me
  • Yocto Hardening
  • Mailing List

Yocto Hardening: dm-verity

In this part of the Yocto hardening we talk about how to verify the integrity of a file system with dm-verity in embedded systems.

Continue reading...
May 6, 2026 by ejaaskel Security

Yocto Hardening: Read-Only Rootfs

Let’s continue the always-so-fun task of hardening the Yocto systems. This time, we will consider the file system integrity.

Continue reading...
April 22, 2026 by ejaaskel Security

Sandboxing Systemd Services

Systemd has security features that tend to go underutilised. Especially, the service files have sandboxing features that can be used to isolate the service.

Continue reading...
February 8, 2026 by ejaaskel Linux

Building Sulka: Six Months of Embedded Linux Development

Half a year ago, I started a little hobby project of building a hardened Yocto distro, Sulka. I thought that I’d share what’s happened over the past months.

Continue reading...
December 21, 2025 by ejaaskel Sulka

“Fun” with SELinux

A few weeks ago, I had some (mis)adventures with SELinux, and after spending almost a whole week debugging weird issues, I felt like I needed to vent a bit.

Continue reading...
December 11, 2025 by ejaaskel Random ramblings

Protecting U-Boot Command Line

This text should help you harden U-Boot by fixing the lowest-hanging fruit: unfettered access to the bootloader control interface.

Continue reading...
November 5, 2025 by ejaaskel Security

Module Signing Keys (Without Building Kernel)

In this blog post we will talk about module signing keys in a situation where the entity developing and signing kernel modules cannot build in their keys.

Continue reading...
September 30, 2025 by ejaaskel Linux

Yocto Hardening: Kernel Module Signing

This time we have a relatively simple and effective hardening measure that may prevent big headaches: kernel module signing.

Continue reading...
September 22, 2025 by ejaaskel Yocto

Thinking Outside the (Linux) Box: Security Considerations From Human Actors

This text is a short summary of my presentation at the embedded Linux conference, and talks about humans and cybersecurity.

Continue reading...
August 27, 2025 by ejaaskel Random ramblings

Yocto Hardening: Multi-Factor Authentication

In this blog post, I’ll show how to integrate Google Authenticator into a Yocto system to enhance the security of remote login flows.

Continue reading...
July 2, 2025 by ejaaskel Yocto
Page 1 of 612345...»Last »
  • Recent Posts
  • Recent Comments
  • Tags
  • Security

    Yocto Hardening: dm-verity

    May 6, 2026

  • Security

    Yocto Hardening: Read-Only Rootfs

    April 22, 2026

  • Linux

    Sandboxing Systemd Services

    February 8, 2026

  • Sulka

    Building Sulka: Six Months of Embedded Linux Development

    December 21, 2025

  • Random ramblings

    “Fun” with SELinux

    December 11, 2025

  • F. Mellmann says:
    Thanks a lot for your very helpful description! I've struggled a...
  • Shashank P says:
    Thank you very much ! .. Helped me get going on...
  • ejaaskel says:
    That seems to be a solid choice, thanks for the suggestion.
  • ejaaskel says:
    Thanks, great to hear you like it! I have planned the...
  • Joel says:
    Ohh, and ARM SoC with a FPGA called Avnet Zuboard 1CG...
  • aioli audio programming block design busybox c++ configuration delayyyyyy devblog digitalocean dns embedded embedded linux emulation encryption file systems firewall fpga fuzzing hardening juce kernel linux measured boot namesilo neorv32 open source pain programming projects qemu raspberry pi releases rtos security sulka syzkaller testing tpm tutorial u-boot vst plugins wordpress wsl yocto zephyr

Get in Touch


If you're sending me LinkedIn message, please mention that you're coming from the blog.

ejaaskel © 2026. All Rights Reserved.

Powered by WordPress. Theme by Alx.