Compiler Can Undo Your Security Checks
Recorded: Sept. 12, 2026, 3:09 p.m.
| Original | Summarized |
Your Compiler Can Undo Your Security Checks - Davidbombal HomeCoursesFree Free SoftwareFree QuizMotivationAbout UsContact UsSign In Your Compiler Can Undo Your Security Checks Big thanks to @ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.// Christopher Domas’ SOCIAL // LinkedIn: / christopher-domas GitHub: https://github.com/xoreaxeaxeax X: https://x.com/xoreaxeaxeax // David’s Social //================ Coect with me: ================ Discord: http://discord.davidbombal.com X: https://www.x.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube Main https://www.youtube.com/davidbombal YouTube Tech: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A YouTube Clips: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q YouTube Emerging Technologies: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q YouTube Shorts: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg Apple Podcast: https://davidbombal.wiki/applepodcast Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ SoundCloud: / davidbombal ================ Support me: ================ Or, buy my CCNA course and support me: DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna Udemy CCNA Course: https://bit.ly/ccnafor10dollars GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10// MY STUFF // https://www.amazon.com/shop/davidbombal// SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com// MENU // 0:00 – Coming Up 0:48 – Intro 02:05 – Different Ways of Exploiting CPU’s 04:10 – The C Specifications 06:17 – The Compiler Deleting Nemsec 08:40 – Do we need to use a new Compiler ? 10:09 – Compiler Inventing Vulnerabilities 12:13 – Don’t Give up Writing Secure Code 12:44 – Sponsored Section 14:25 – Any Easy Options To Create A New Compiler ? 15:09 – Chris’s Presentation at Black Hat 20:00 – Weird Situations with Size of Data 21:22 – What Can Developers Do ? 23:32 – Who Can Leverage this Vulnerability ? 25:02 – Could AI Make it Easy For Attackers To Leverage This? 28:27 – Recommendations For Developers 29:48 – Advice To Be Like Chris 30:36 – Conclusion & OutroPlease note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!Disclaimer: This video is for educational purposes only. #bhusa2026 #securecoding #compiler David Bombal September 4, 2026 Cyber Security secure coding Search CategoriesArtificial IntelligenceCCNAChat GPTCiscoCloudCyber SecurityFlipper ZeroGNS3HackingLinuxNetHunterNetworkingPrivacyProgramming LanguagePythonRaspberry piUncategorizedWiresharkRecent Posts LockBit Infiltration Explained (18 Months Inside) September 8, 2026 Age Verification: The Privacy Risk You Need to Know September 6, 2026 Pixel Phone Zero-Click Hack Explained (Full Attack Chain) September 4, 2026 Your Compiler Can Undo Your Security Checks September 4, 2026 How to Extract the Game Boy Boot ROM From a Chip Photo September 1, 2026 This Pocket Tool Diagnoses Wi-Fi in 45 Seconds August 30, 2026 AI Is Changing Cybersecurity. Here’s How to Defend Yourself August 26, 2026 Hacking Gadgets Every Cybersecurity Pro Should Know August 23, 2026 How to install Qubes OS and replace Windows (step by step) August 18, 2026 Cybersecurity Is Broken: Here’s What Needs to Change August 16, 2026Give us a follow Get in touch with us! If you have other issues or non-course questions, send us an email at support@davidbombal.com. |
The fundamental issue discussed is that even when writing secure C code, developers can still end up with vulnerable binaries because the Central Processing Unit does not execute the source code directly; instead, it executes the machine code produced by the compiler. This dynamic allows legal compiler optimizations to effectively remove security protections, eliminate necessary memory-clearing operations, and introduce time-of-check to time-of-use vulnerabilities into code that initially appeared secure. Chris Domas examined this phenomenon by exploring the C abstract machine, the extent to which compilers are permitted to perform dramatic transformations on code, and how factors such as register pressure, structure layout, and data size influence the vulnerability status of a resulting binary. For instance, a specific finding demonstrated that small variations in data size, such as seventeen or thirty-three bytes, can create safe code, whereas nearby size variations can introduce exploitable vulnerabilities. The discussion further addressed related development and tooling choices. Researchers explored whether modern languages like Rust inherently solve these compiler-related security issues, and clarified that switching between compilers such as GCC and Clang is not a definitive solution. Additionally, the importance of analyzing large codebases was highlighted, noting that artificial intelligence has been instrumental in analyzing half a billion lines of open-source code to identify approximately three hundred potentially dangerous patterns. Ultimately, the text emphasizes actionable steps for developers to mitigate these risks. These recommendations include enabling compiler warnings, utilizing sanitizers during compilation, rigorously analyzing optimized builds, and performing thorough testing on the exact binary that is intended for distribution. The overarching theme is that developers must adopt practices that account for the compiler’s behavior to ensure true security. |