Dominic Rizzo - Silicon Roots of Trust: Attestation You'd Want Even If Nobody Required It
Dominic Rizzo (zeroRISC) presents open-source silicon roots of trust as a mature, commercially viable solution for hardware security and attestation. The technology, proven at scale in Chromebooks and data centers through his OpenTitan project, enables end users to control what software runs on devices they purchase—a capability currently absent despite ownership. Three forces drive adoption: AI infrastructure buildout, mandated post-quantum cryptography transition by 2030, and mature open-source designs that shift the cost calculus from burden to necessity. Unlike confidential VMs requiring trust in chip makers and cloud providers, bare-metal attestation removes intermediaries from the trust chain. The technology enables supply chain provenance, workload attestation, perfect recoverability, and below-the-metal firmware updates. While regulatory mandates like Europe's Cyber Resilience Act push adoption, Rizzo argues liability shields for implementing NIST-standardized best practices would better align chip maker incentives than punitive approaches alone. Note: The opinions shared in this event are those of the speaker(s) and may not represent the views of FAR.AI or their affiliated organizations.